Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25853 | IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7179558 |
|
Fri, 15 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:security_directory_integrator:*:*:*:*:*:*:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Dec 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | |
| Title | IBM Security Directory Integrator command execution | |
| First Time appeared |
Ibm
Ibm security Directory Integrator |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:security_directory_integrator:10.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_directory_integrator:10.0.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_directory_integrator:7.2.0.13:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_directory_integrator:7.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm security Directory Integrator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-12-20T17:36:37.326Z
Reserved: 2024-03-10T12:22:43.138Z
Link: CVE-2024-28767
Updated: 2024-12-20T16:34:56.956Z
Status : Analyzed
Published: 2024-12-20T14:15:23.850
Modified: 2025-08-15T18:28:22.810
Link: CVE-2024-28767
No data.
OpenCVE Enrichment
No data.
EUVD