Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2025-13356 | IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 
Solution
IBM Cloud Pak for Business Automation V24.0.1 - V24.0.1-IF001 Apply security fix 24.0.1-IF002 IBM Cloud Pak for Business Automation V24.0.0 - V24.0.0-IF004 Apply security fix 24.0.0-IF005 or upgrade to 24.0.1-IF002
Workaround
No workaround given by the vendor.
| Link | Providers | 
|---|---|
| https://www.ibm.com/support/pages/node/7232197 |     | 
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:-:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_001:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_002:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_003:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_004:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:-:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_001:*:*:*:*:*:* | 
Mon, 05 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Sat, 03 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM Cloud Pak for Business Automation cross-site scripting | |
| First Time appeared | Ibm Ibm cloud Pak For Business Automation | |
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_business_automation:23.0.1:if001:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:if004:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:* | |
| Vendors & Products | Ibm Ibm cloud Pak For Business Automation | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-28T14:28:03.413Z
Reserved: 2024-07-22T12:02:37.814Z
Link: CVE-2024-41753
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-05-05T14:40:28.816Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-05-03T16:15:19.150
Modified: 2025-08-14T01:51:25.910
Link: CVE-2024-41753
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.