cve-2024-43188
Vulnerability from cvelistv5
Published
2024-09-18 11:39
Modified
2024-09-18 16:40
Severity ?
EPSS score ?
Summary
IBM Business Automation Workflow improper input validation
References
▼ | URL | Tags | |
---|---|---|---|
psirt@us.ibm.com | https://www.ibm.com/support/pages/node/7168769 | Vendor Advisory |
Impacted products
▼ | Vendor | Product |
---|---|---|
IBM | Business Automation Workflow |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2024-43188", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-09-18T13:23:48.735450Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-09-18T13:23:58.053Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:ibm:business_automation_workflow:22.0.2:*:*:*:-:*:*:*", "cpe:2.3:a:ibm:business_automation_workflow:23.0.1:*:*:*:-:*:*:*", "cpe:2.3:a:ibm:business_automation_workflow:23.0.2:*:*:*:-:*:*:*", "cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:-:*:*:*" ], "defaultStatus": "unaffected", "product": "Business Automation Workflow", "vendor": "IBM", "versions": [ { "status": "affected", "version": "22.0.2, 23.0.1, 23.0.2, 24.0.0" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eIBM Business Automation Workflow \n\n\u003cspan style=\"background-color: rgb(244, 244, 244);\"\u003e22.0.2, 23.0.1, 23.0.2, and 24.0.0\u003c/span\u003e\n\ncould allow a privileged user to perform unauthorized activities due to improper client side validation.\u003c/span\u003e" } ], "value": "IBM Business Automation Workflow \n\n22.0.2, 23.0.1, 23.0.2, and 24.0.0\n\ncould allow a privileged user to perform unauthorized activities due to improper client side validation." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 4.9, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-602", "description": "CWE-602 Client-Side Enforcement of Server-Side Security", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-09-18T16:40:53.717Z", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "tags": [ "vendor-advisory" ], "url": "https://www.ibm.com/support/pages/node/7168769" } ], "source": { "discovery": "UNKNOWN" }, "title": "IBM Business Automation Workflow improper input validation", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2024-43188", "datePublished": "2024-09-18T11:39:22.958Z", "dateReserved": "2024-08-07T13:29:34.029Z", "dateUpdated": "2024-09-18T16:40:53.717Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2024-43188\",\"sourceIdentifier\":\"psirt@us.ibm.com\",\"published\":\"2024-09-18T12:15:02.867\",\"lastModified\":\"2024-09-29T00:24:49.103\",\"vulnStatus\":\"Analyzed\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"IBM Business Automation Workflow \\n\\n22.0.2, 23.0.1, 23.0.2, and 24.0.0\\n\\ncould allow a privileged user to perform unauthorized activities due to improper client side validation.\"},{\"lang\":\"es\",\"value\":\"IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2 y 24.0.0 podr\u00edan permitir que un usuario privilegiado realice actividades no autorizadas debido a una validaci\u00f3n incorrecta del lado del cliente.\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"HIGH\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"NONE\",\"baseScore\":4.9,\"baseSeverity\":\"MEDIUM\"},\"exploitabilityScore\":1.2,\"impactScore\":3.6},{\"source\":\"psirt@us.ibm.com\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"HIGH\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"NONE\",\"baseScore\":4.9,\"baseSeverity\":\"MEDIUM\"},\"exploitabilityScore\":1.2,\"impactScore\":3.6}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"NVD-CWE-Other\"}]},{\"source\":\"psirt@us.ibm.com\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-602\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:traditional:*:*:*\",\"versionStartIncluding\":\"18.0.0.1\",\"versionEndIncluding\":\"18.0.0.3\",\"matchCriteriaId\":\"F74D99AD-0570-49B3-9B0D-6F28FA9564B4\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:traditional:*:*:*\",\"versionStartIncluding\":\"19.0.0.1\",\"versionEndIncluding\":\"19.0.0.3\",\"matchCriteriaId\":\"DB90C98C-7A38-4B9B-878C-028DD872D19C\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:traditional:*:*:*\",\"versionStartIncluding\":\"21.0.1\",\"versionEndIncluding\":\"21.0.3.1\",\"matchCriteriaId\":\"47064639-B3A7-4F99-8823-40D2C9FE3C1A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:20.0.0.1:*:*:*:traditional:*:*:*\",\"matchCriteriaId\":\"D36329EB-4317-4AB1-85FA-4E23F185C179\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:20.0.0.2:*:*:*:traditional:*:*:*\",\"matchCriteriaId\":\"8C7FDEC2-CBE3-4C5B-917D-37F2612018FB\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:22.0.1:*:*:*:traditional:*:*:*\",\"matchCriteriaId\":\"8C6D1E72-FC9F-4A0A-8E80-A3CA8CB0EDAA\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:22.0.2:*:*:*:traditional:*:*:*\",\"matchCriteriaId\":\"DFB13BEC-206E-41B3-A4F3-9281EBB0E213\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:23.0.1:*:*:*:traditional:*:*:*\",\"matchCriteriaId\":\"F7C0BC37-0F42-463F-B2E4-F2B3D3958314\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:23.0.2:*:*:*:traditional:*:*:*\",\"matchCriteriaId\":\"7E9F20F6-4D3B-4AD6-9F6B-E145598FFEE2\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:traditional:*:*:*\",\"matchCriteriaId\":\"95CE7462-D6B6-41AE-BD90-E2D65E0318A3\"}]}]}],\"references\":[{\"url\":\"https://www.ibm.com/support/pages/node/7168769\",\"source\":\"psirt@us.ibm.com\",\"tags\":[\"Vendor Advisory\"]}]}}" } }
Loading...
Loading...
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.