CVE-2024-38324: IBM Storage Defender
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.
Affected products
- IBM Storage Defender: from 2.0.0, before 2.0.8 (fixed in 2.0.8)
Published 2024-09-25. Last modified 2026-06-17.