Description
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.
Published: 2024-09-04
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-41297 IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.
History

Mon, 29 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-308

Mon, 29 Sep 2025 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Fri, 06 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm webmethods Integration
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:ibm:webmethods_integration:10.15:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm webmethods Integration

Wed, 04 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Sep 2024 16:15:00 +0000

Type Values Removed Values Added
Description IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.
Title IBM webMethods Integration privilege escalation
First Time appeared Softwareag
Softwareag webmethods
Weaknesses CWE-308
CPEs cpe:2.3:a:softwareag:webmethods:10.15:*:*:*:*:*:*:*
Vendors & Products Softwareag
Softwareag webmethods
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Webmethods Integration
Softwareag Webmethods
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-29T17:52:58.134Z

Reserved: 2024-08-21T19:10:49.905Z

Link: CVE-2024-45075

cve-icon Vulnrichment

Updated: 2024-09-04T16:18:38.269Z

cve-icon NVD

Status : Modified

Published: 2024-09-04T16:15:08.357

Modified: 2025-09-29T18:15:30.673

Link: CVE-2024-45075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses