CVE Vulnerabilities

CVE-2024-28766

Exposure of Information Through Directory Listing

Published: Jan 27, 2025 | Modified: Jul 14, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

NameVendorStart VersionEnd Version
Security_directory_integratorIbm7.2.0 (including)7.2.0 (including)
Security_verify_directory_integratorIbm10.0.0 (including)10.0.0 (including)

Potential Mitigations

References