IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
History

Fri, 28 Mar 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Mon, 30 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 30 Dec 2024 14:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
Title IBM WebSphere Automation command injection
First Time appeared Ibm
Ibm websphere Automation
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:websphere_automation:1.7.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Automation
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-12-30T14:12:56.069Z

Reserved: 2024-11-30T14:47:55.533Z

Link: CVE-2024-54181

cve-icon Vulnrichment

Updated: 2024-12-30T14:12:52.124Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-30T14:15:05.867

Modified: 2025-03-28T16:32:40.990

Link: CVE-2024-54181

cve-icon Redhat

No data.