CVE-2024-54179

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 3, 2025
CWE ID 79

Summary

CVE-2024-54179 is a newly disclosed cross-site scripting (XSS) vulnerability affecting IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus versions 24.0.0 and 24.0.1, as well as unsupported earlier releases. This issue enables authenticated users to inject arbitrary JavaScript code into the web user interface, enabling attackers to potentially steal sensitive information, including credentials, within a trusted session. IBM urges users to upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share