CVE-2024-31916

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
27/06/2024
Last modified:
06/08/2024

Description

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:* fw1050.00 (including) fw1050.10 (including)