First published: Tue Feb 04 2025(Updated: )
IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | ||
IBM Cloud Pak for Business Automation | =18.0.0=18.0.1=18.0.2=19.0.1=19.0.2=19.0.3=20.0.1=20.0.2=20.0.3=21.0.1=21.0.2=21.0.3=22.0.1=22.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52365 is classified as a high severity vulnerability due to the potential for credentials disclosure through stored cross-site scripting.
To mitigate CVE-2024-52365, update your IBM Business Automation Workflow or IBM Cloud Pak for Business Automation to the latest patched version provided by IBM.
CVE-2024-52365 affects authenticated users of IBM Business Automation Workflow and IBM Cloud Pak for Business Automation versions listed in the vulnerability report.
CVE-2024-52365 is a stored cross-site scripting vulnerability which allows users to inject arbitrary JavaScript into the Web UI.
Yes, CVE-2024-52365 can lead to significant security breaches, including the potential exposure of user credentials within a trusted session.