First published: Fri May 02 2025(Updated: )
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Business Automation | >=24.0.0<=24.0.0 IF004>=24.0.1<24.0.1 IF001 | |
IBM Cloud Pak for Business Automation |
IBM Cloud Pak for Business Automation V24.0.1 - V24.0.1-IF001 Apply security fix 24.0.1-IF002 IBM Cloud Pak for Business Automation V24.0.0 - V24.0.0-IF004 Apply security fix 24.0.0-IF005 or upgrade to 24.0.1-IF002
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41753 has been assigned a moderate severity level due to its ability to allow unauthenticated cross-site scripting attacks.
To fix CVE-2024-41753, you should update your IBM Cloud Pak for Business Automation to version 24.0.1 IF002 or higher, which contains the necessary security patches.
The CVE-2024-41753 vulnerability can allow attackers to execute arbitrary JavaScript code, potentially compromising user data and application integrity.
IBM Cloud Pak for Business Automation versions 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 are affected by CVE-2024-41753.
Yes, CVE-2024-41753 can be exploited by unauthenticated users, making it particularly concerning for web applications.