First published: Tue Feb 04 2025(Updated: )
IBM Business Automation Workflow allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Business Automation | >=18.0.0<=22.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49348 is rated as a high-severity vulnerability due to its potential for unauthorized access to sensitive data.
To mitigate CVE-2024-49348, update your IBM Cloud Pak for Business Automation to version 22.0.3 or later.
CVE-2024-49348 affects IBM Cloud Pak for Business Automation versions 18.0.0 through 22.0.2.
CVE-2024-49348 may result in unauthorized access to organizational data through user queries.
Currently, there are no official workarounds for CVE-2024-49348 other than applying the recommended updates.