First published: Thu Oct 05 2023(Updated: )
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Business Automation | <=V23.0.1 - V23.0.1-IF002 | |
IBM Cloud Pak for Business Automation | <=V21.0.3 - V21.0.3-IF024 | |
IBM Cloud Pak for Business Automation | <=V22.0.2 - V22.0.2-IF006 and later fixesV22.0.1 - V22.0.1-IF006 and later fixesV21.0.2 - V21.0.2-IF012 and later fixesV21.0.1 - V21.0.1-IF007 and later fixesV20.0.1 - V20.0.3 and later fixesV19.0.1 - V19.0.3 and later fixesV18.0.0 - V18.0.2 and later fixes | |
IBM Cloud Pak for Business Automation | =18.0.0 | |
IBM Cloud Pak for Business Automation | =18.0.1 | |
IBM Cloud Pak for Business Automation | =18.0.2 | |
IBM Cloud Pak for Business Automation | =19.0.1 | |
IBM Cloud Pak for Business Automation | =19.0.2 | |
IBM Cloud Pak for Business Automation | =19.0.3 | |
IBM Cloud Pak for Business Automation | =20.0.1 | |
IBM Cloud Pak for Business Automation | =20.0.2 | |
IBM Cloud Pak for Business Automation | =20.0.3 | |
IBM Cloud Pak for Business Automation | =21.0.1 | |
IBM Cloud Pak for Business Automation | =21.0.2 | |
IBM Cloud Pak for Business Automation | =21.0.3 | |
IBM Cloud Pak for Business Automation | =22.0.1 | |
IBM Cloud Pak for Business Automation | =22.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35024 is a vulnerability in IBM Business Automation Workflow that allows for cross-site scripting.
CVE-2023-35024 has a severity rating of 4.6 out of 10, which is considered medium.
CVE-2023-35024 affects IBM Cloud Pak for Business Automation versions 18.0.0 to 22.0.2, allowing users to embed arbitrary JavaScript code and potentially alter the intended functionality of the Web UI.
To fix CVE-2023-35024, it is recommended to apply the latest available fixes and patches provided by IBM for Cloud Pak for Business Automation.
You can find more information about CVE-2023-35024 on the IBM X-Force Exchange website and the IBM Support Pages.