CVE-2024-38325: IBM Storage Defender

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

Affected products

  • IBM Storage Defender: from 2.0.0, before 2.0.8 (fixed in 2.0.8)

Published 2025-01-27. Last modified 2026-06-17.