CVE-2024-38327
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which could assist an attacker to read and debug JavaScript used in the application's API.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.28%
- CWE
- CWE-540
- Published
- 2025-07-10
- Last modified
- 2026-03-13
Affected products
- IBM Analytics Content Hub
Weakness type
Related vulnerabilities
- CVE-2026-16581 — Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application
- CVE-2026-45728 — Algernon: Single-file mode unconditionally enables debug mode
- CVE-2026-4155 — ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability
- CVE-2026-35383 — Bentley Systems iTwin Platform exposed access token
- CVE-2026-22275 — Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0,...
- CVE-2025-36299 — IBM Planning Analytics Information Disclosure
- CVE-2025-49182 — Credential disclosure
- CVE-2025-0923 — IBM Cognos Analytics information disclosure