CVE-2023-35024: IBM Cloud Pak for Business Automation cross-site scripting
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 258349.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-35024?
CVE-2023-35024 is a vulnerability in IBM Business Automation Workflow that allows for cross-site scripting.
What is the severity of CVE-2023-35024?
CVE-2023-35024 has a severity rating of 4.6 out of 10, which is considered medium.
How does CVE-2023-35024 affect IBM Cloud Pak for Business Automation?
CVE-2023-35024 affects IBM Cloud Pak for Business Automation versions 18.0.0 to 22.0.2, allowing users to embed arbitrary JavaScript code and potentially alter the intended functionality of the Web UI.
How can I fix CVE-2023-35024?
To fix CVE-2023-35024, it is recommended to apply the latest available fixes and patches provided by IBM for Cloud Pak for Business Automation.
Where can I find more information about CVE-2023-35024?
You can find more information about CVE-2023-35024 on the IBM X-Force Exchange website and the IBM Support Pages.