could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46202 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7180303 |
|
Fri, 18 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 |
Tue, 07 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Jan 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization. | |
| Title | IBM Concert Software log manipulation | |
| First Time appeared |
Ibm
Ibm concert |
|
| Weaknesses | CWE-117 | |
| CPEs | cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:concert:1.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:concert:1.0.2.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:concert:1.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:concert:1.0.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm concert |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-01-07T14:47:44.238Z
Reserved: 2024-11-17T14:25:44.933Z
Link: CVE-2024-52891
Updated: 2025-01-07T14:47:38.535Z
Status : Analyzed
Published: 2025-01-07T12:15:25.010
Modified: 2025-07-18T13:39:22.407
Link: CVE-2024-52891
No data.
OpenCVE Enrichment
No data.
EUVD