This page lists publicly disclosed CVE vulnerabilities affecting ibm analytics_content_hub (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-36090 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be used in reconnaissance to gather information for future attacks from a detailed technical error message. | [email protected] | 4.3 | 0.16% | 2025-07-10 | 2025-07-23 |
| CVE-2024-39752 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore Content. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks. | [email protected] | 6.8 | 0.19% | 2025-07-10 | 2025-07-23 |
| CVE-2024-38327 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which could assist an attacker to read and debug JavaScript used in the application's API. | [email protected] | 6.8 | 0.19% | 2025-07-10 | 2025-07-23 |
| CVE-2024-37524 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. | [email protected] | 5.3 | 0.19% | 2025-07-10 | 2025-07-23 |
| CVE-2024-39750 | IBM Analytics Content Hub 2.0 is vulnerable to a buffer overflow due to improper return length checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | [email protected] | 8.8 | 1.49% | 2025-01-25 | 2025-09-29 |
| CVE-2024-35134 | IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | [email protected] | 5.3 | 0.08% | 2025-01-25 | 2025-07-25 |