Description
IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54410 | IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. |
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7230848 |
|
History
Tue, 19 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:*:*:*:*:*:*:*:* |
Mon, 14 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. | |
| Title | IBM Robotic Process Automation session fixation | |
| First Time appeared |
Ibm
Ibm robotic Process Automation Ibm robotic Process Automation For Cloud Pak |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ibm:robotic_process_automation:21.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:21.0.7.20:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:23.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:23.0.20:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:21.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:21.0.7.20:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:23.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:23.0.20:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm robotic Process Automation Ibm robotic Process Automation For Cloud Pak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-01T00:54:05.019Z
Reserved: 2024-10-20T13:40:37.122Z
Link: CVE-2024-49825
Updated: 2025-04-14T15:03:15.525Z
Status : Analyzed
Published: 2025-04-14T15:15:23.627
Modified: 2025-08-19T16:49:41.707
Link: CVE-2024-49825
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD