CVE-2024-41753: IBM Cloud Pak for Business Automation cross-site scripting
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM CP4BA - Business Automation Insights Core is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41753?
CVE-2024-41753 has been assigned a moderate severity level due to its ability to allow unauthenticated cross-site scripting attacks.
How do I fix CVE-2024-41753?
To fix CVE-2024-41753, you should update your IBM Cloud Pak for Business Automation to version 24.0.1 IF002 or higher, which contains the necessary security patches.
What impact does CVE-2024-41753 have on my application?
The CVE-2024-41753 vulnerability can allow attackers to execute arbitrary JavaScript code, potentially compromising user data and application integrity.
Is my version of IBM Cloud Pak for Business Automation affected by CVE-2024-41753?
IBM Cloud Pak for Business Automation versions 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 are affected by CVE-2024-41753.
Can unauthenticated users exploit CVE-2024-41753?
Yes, CVE-2024-41753 can be exploited by unauthenticated users, making it particularly concerning for web applications.