CVE-2024-52365: IBM Cloud Pak for Business Automation cross-site scripting
IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2
is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52365?
CVE-2024-52365 is classified as a high severity vulnerability due to the potential for credentials disclosure through stored cross-site scripting.
How do I fix CVE-2024-52365?
To mitigate CVE-2024-52365, update your IBM Business Automation Workflow or IBM Cloud Pak for Business Automation to the latest patched version provided by IBM.
Who is affected by CVE-2024-52365?
CVE-2024-52365 affects authenticated users of IBM Business Automation Workflow and IBM Cloud Pak for Business Automation versions listed in the vulnerability report.
What type of vulnerability is CVE-2024-52365?
CVE-2024-52365 is a stored cross-site scripting vulnerability which allows users to inject arbitrary JavaScript into the Web UI.
Can CVE-2024-52365 lead to any serious outcomes?
Yes, CVE-2024-52365 can lead to significant security breaches, including the potential exposure of user credentials within a trusted session.