CVE-2024-31916: IBM Openbmc

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.

Affected products

  • IBM Openbmc: from fw1050.00, up to and including fw1050.10

Published 2024-06-27. Last modified 2026-06-17.