First published: Fri Feb 21 2025(Updated: )
IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privilege management.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.2 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.1 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22341 is considered a high-severity vulnerability due to the potential for unauthorized data access.
To fix CVE-2024-22341, update to a patched version of IBM Watson Query or IBM Data Virtualization on Cloud Pak for Data as specified in the vendor's security advisories.
CVE-2024-22341 affects versions of IBM Watson Query on Cloud Pak for Data from 4.0.0 through 4.8.7 and IBM Data Virtualization on Cloud Pak for Data from 1.7 through 3.0.
CVE-2024-22341 exposes risks of unauthorized access to data from remote data source objects.
CVE-2024-22341 can be exploited by remote attackers who improperly gain access due to privilege management issues.