First published: Sat Aug 03 2024(Updated: )
IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations that could be read by an authenticated user. IBM X-Force ID: 284868.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | =20.0.0.1 | |
IBM Business Automation Workflow | =20.0.0.2 | |
IBM Business Automation Workflow | =21.0.2 | |
IBM Business Automation Workflow | =21.0.3 | |
IBM Business Automation Workflow | =21.0.3-if002 | |
IBM Business Automation Workflow | =21.0.3-if005 | |
IBM Business Automation Workflow | =21.0.3-if006 | |
IBM Business Automation Workflow | =21.0.3-if007 | |
IBM Business Automation Workflow | =21.0.3-if008 | |
IBM Business Automation Workflow | =21.0.3-if009 | |
IBM Business Automation Workflow | =21.0.3-if010 | |
IBM Business Automation Workflow | =21.0.3-if011 | |
IBM Business Automation Workflow | =21.0.3-if012 | |
IBM Business Automation Workflow | =21.0.3-if013 | |
IBM Business Automation Workflow | =21.0.3-if014 | |
IBM Business Automation Workflow | =21.0.3-if015 | |
IBM Business Automation Workflow | =21.0.3-if016 | |
IBM Business Automation Workflow | =21.0.3-if017 | |
IBM Business Automation Workflow | =21.0.3-if028 | |
IBM Business Automation Workflow | =21.0.3-if029 | |
IBM Business Automation Workflow | =21.0.3-if030 | |
IBM Business Automation Workflow | =21.0.3-if031 | |
IBM Business Automation Workflow | =21.0.3-if032 | |
IBM Business Automation Workflow | =21.0.3-if033 | |
IBM Business Automation Workflow | =21.0.3-if034 | |
IBM Business Automation Workflow | =22.0.1 | |
IBM Business Automation Workflow | =22.0.2 | |
IBM Business Automation Workflow | =23.0.1 | |
IBM Business Automation Workflow | =23.0.2 | |
IBM Business Automation Workflow | >=19.0.0.1<=19.0.0.3 | |
IBM Business Automation Workflow | >=20.0.0.1<=20.0.0.2 | |
IBM Business Automation Workflow | >=21.0.1<=21.0.3.0 | |
IBM Business Automation Workflow | >=22.0.1<=22.0.2 | |
IBM Business Automation Workflow | >=23.0.1<=23.0.2 | |
IBM Business Automation Workflow | >=23.0.1<=23.0.2 | |
IBM Business Automation Workflow | =22.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38321 has been classified as a moderate severity vulnerability due to the potential exposure of sensitive information to authenticated users.
CVE-2024-38321 affects IBM Business Automation Workflow versions 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, 23.0.2, and 24.0.0.
To address CVE-2024-38321, you should update your IBM Business Automation Workflow to a fixed version that is not susceptible to this vulnerability.
CVE-2024-38321 involves the storage of potentially sensitive information in log files, which can be accessed by authenticated users.
Yes, exploitation of CVE-2024-38321 requires an authenticated user to access the potentially sensitive information stored in log files.