IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation.
History

Sun, 29 Sep 2024 00:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:20.0.0.1:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:20.0.0.2:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:22.0.1:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:22.0.2:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:23.0.1:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:23.0.2:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:traditional:*:*:*

Wed, 18 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 11:45:00 +0000

Type Values Removed Values Added
Description IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation.
Title IBM Business Automation Workflow improper input validation
First Time appeared Ibm
Ibm business Automation Workflow
Weaknesses CWE-602
CPEs cpe:2.3:a:ibm:business_automation_workflow:22.0.2:*:*:*:-:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:23.0.1:*:*:*:-:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:23.0.2:*:*:*:-:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:-:*:*:*
Vendors & Products Ibm
Ibm business Automation Workflow
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2024-09-18T11:39:22.958Z

Updated: 2024-09-18T16:40:53.717Z

Reserved: 2024-08-07T13:29:34.029Z

Link: CVE-2024-43188

cve-icon Vulnrichment

Updated: 2024-09-18T13:23:52.983Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-18T12:15:02.867

Modified: 2024-09-29T00:24:49.103

Link: CVE-2024-43188

cve-icon Redhat

No data.