CVE-2024-54179: IBM Business Automation Workflow cross-site scripting
IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54179?
CVE-2024-54179 has been classified as a moderate severity vulnerability, allowing for cross-site scripting attacks.
How do I fix CVE-2024-54179?
To fix CVE-2024-54179, update IBM Business Automation Workflow or IBM Business Automation Workflow Enterprise Service Bus to a version later than 24.0.1.
Who is affected by CVE-2024-54179?
CVE-2024-54179 affects users of IBM Business Automation Workflow versions 24.0.0 to 24.0.1 and IBM Business Automation Workflow Enterprise Service Bus versions 24.0.0 to 24.0.1.
What type of attack does CVE-2024-54179 enable?
CVE-2024-54179 enables authenticated users to conduct cross-site scripting (XSS) attacks by embedding arbitrary JavaScript code.
Is CVE-2024-54179 a local or remote vulnerability?
CVE-2024-54179 is a remote vulnerability, as it can be exploited through the web interface by authenticated users.