IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server.
CVE ID: CVE-2024-52899
CVSS Base Severity: HIGH
CVSS Base Score: 8.5
Vendor: IBM
Product: Data Virtualization Manager for z/OS
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.44% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)