IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7182522 |
|
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm applinx |
|
| CPEs | cpe:2.3:a:ibm:applinx:11.1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm applinx |
Thu, 06 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Feb 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Title | IBM ApplinX Information Disclosure | |
| Weaknesses | CWE-327 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-02-05T23:48:23.728Z
Updated: 2025-02-22T22:06:18.823Z
Reserved: 2024-10-20T13:40:16.212Z
Link: CVE-2024-49797
Updated: 2025-02-06T15:03:06.337Z
Status : Analyzed
Published: 2025-02-06T00:15:27.330
Modified: 2025-02-12T19:17:11.273
Link: CVE-2024-49797
No data.