Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38017 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7176783 |
|
Fri, 10 Jan 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm engineering Lifecycle Optimization - Engineering Insights
|
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_engineering_insights:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_engineering_insights:7.0.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm engineering Lifecycle Optimization - Engineering Insights
|
Thu, 26 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Dec 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. | |
| Title | IBM Engineering Lifecycle Optimization - Engineering Insights tabnabbing | |
| First Time appeared |
Ibm
Ibm engineering Insights |
|
| Weaknesses | CWE-1022 | |
| CPEs | cpe:2.3:a:ibm:engineering_insights:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:engineering_insights:7.0.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm engineering Insights |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-12-26T18:11:41.366Z
Reserved: 2024-06-28T09:34:20.322Z
Link: CVE-2024-39727
Updated: 2024-12-26T18:11:37.669Z
Status : Analyzed
Published: 2024-12-25T14:15:22.610
Modified: 2025-01-10T20:15:39.980
Link: CVE-2024-39727
No data.
OpenCVE Enrichment
No data.
EUVD