CNNVD-202509-1486 Information

CNNVD ID

CNNVD-202509-1486

CVE-2024-47120

  • CNNVD Published: 2025-09-10

Description (Chinese)

IBM Security Verify Information Queue是美国国际商业机器(IBM)公司的一个集成产品。利用 Kafka 技术和发布/订阅模型来集成 IBM Security 产品之间的数据。 IBM Security Verify Information Queue 10.0.5版本、10.0.6版本、10.0.7版本和10.0.8版本存在安全漏洞,该漏洞源于容器运行权限过高,可能导致权限提升。

Description (English)

IBM Security Investment Queue is an integrated product of IBM. kafka technology and distribution/subscription model to integrate data between IBM Security products. The IBM Security Information Queue 10.0.5, 10.0.6, 10.0.7 and 10.0.8 have security loopholes, which stem from the over-capacity of the container, which may lead to an increase in the authorization.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

国际商业机器

Published

2025-09-10

Last Modified

2026-02-24

References

https://www.ibm.com/support/pages/node/7244514

Patch

https://www.ibm.com/support/pages/node/7244514

Share on: