CVE-2024-52364

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 5, 2025
CWE ID 79

Summary

CVE-2024-52364 is a cross-site scripting (XSS) vulnerability affecting IBM Cloud Pak for Business Automation versions 18.0.0 through 22.0.2. Authenticated users can exploit this issue by embedding arbitrary JavaScript code into the Web UI. The code can alter the intended functionality, posing a potential risk of credentials disclosure within a trusted session. This vulnerability could enable attackers to gain unauthorized access to sensitive information or take control of user actions. IBM recommends users to upgrade to the latest available version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM Cloud Pak For Business Automation

Affected Vendors

  • IBM Corporation