CVE Vulnerabilities

CVE-2024-39729

Inclusion of Sensitive Information in Source Code

Published: Jul 15, 2024 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow an authenticated user to obtain sensitive information from source code that could be used in further attacks against the system. IBM X-Force ID: 295968.

Weakness

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

Affected Software

NameVendorStart VersionEnd Version
DatacapIbm9.1.5 (including)9.1.5 (including)
DatacapIbm9.1.6 (including)9.1.6 (including)
DatacapIbm9.1.7 (including)9.1.7 (including)
DatacapIbm9.1.8 (including)9.1.8 (including)
DatacapIbm9.1.9 (including)9.1.9 (including)
Datacap_navigatorIbm**

Potential Mitigations

References