IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI
could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37104 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7168640 |
|
History
Thu, 14 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm storage Defender
|
|
| CPEs | cpe:2.3:a:ibm:storage_defender:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm storage Defender
|
Mon, 27 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Title | IBM Storage Defender information disclosure | |
| First Time appeared |
Ibm
Ibm storage Defender Resiliency Service |
|
| Weaknesses | CWE-311 | |
| CPEs | cpe:2.3:a:ibm:storage_defender_resiliency_service:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_defender_resiliency_service:2.0.7:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm storage Defender Resiliency Service |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-01-27T15:40:30.461Z
Reserved: 2024-06-13T21:43:59.169Z
Link: CVE-2024-38325
Updated: 2025-01-27T15:40:20.335Z
Status : Analyzed
Published: 2025-01-27T16:15:31.117
Modified: 2025-08-14T19:10:41.307
Link: CVE-2024-38325
No data.
OpenCVE Enrichment
No data.
EUVD