CVE-2024-31906: IBM Automation Decision Services information disclosure
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
Other sources
IBM Automation Decision Services allows web pages to be stored locally which can be read by another user on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31906?
CVE-2024-31906 is considered a medium severity vulnerability due to the potential for unauthorized access to locally stored web pages.
How do I mitigate CVE-2024-31906?
To mitigate CVE-2024-31906, you should upgrade to the latest version of IBM Automation Decision Services beyond version 23.0.2.
Who is impacted by CVE-2024-31906?
Users of IBM Automation Decision Services version 23.0.2 and earlier are impacted by CVE-2024-31906.
What is the type of vulnerability for CVE-2024-31906?
CVE-2024-31906 is a local information disclosure vulnerability that allows unauthorized users to read stored web pages.
When was CVE-2024-31906 reported?
CVE-2024-31906 was reported in 2024, specifically affecting version 23.0.2 of IBM Automation Decision Services.