IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which could assist an attacker to read and debug JavaScript used in the application's API.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54770 IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which could assist an attacker to read and debug JavaScript used in the application's API.
Fixes

Solution

IBM Analytics Content Hub 2.0 - 2.3 - Download IBM Cognos Analytics Content Hub 2.4


Workaround

No workaround given by the vendor.

History

Wed, 23 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:ibm:analytics_content_hub:*:*:*:*:*:*:*:*

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00039}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}


Thu, 10 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Jul 2025 14:30:00 +0000

Type Values Removed Values Added
Description IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which could assist an attacker to read and debug JavaScript used in the application's API.
Title IBM Analytics Content Hub information disclosure
First Time appeared Ibm
Ibm analytics Content Hub
Weaknesses CWE-540
CPEs cpe:2.3:a:ibm:analytics_content_hub:2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:analytics_content_hub:2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:analytics_content_hub:2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:analytics_content_hub:2.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm analytics Content Hub
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-18T01:35:53.589Z

Reserved: 2024-06-13T21:43:59.170Z

Link: CVE-2024-38327

cve-icon Vulnrichment

Updated: 2025-07-10T20:15:39.306Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-10T15:15:25.833

Modified: 2025-07-23T19:04:06.280

Link: CVE-2024-38327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.