First published: Mon Mar 03 2025(Updated: )
IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0 and 24.0.1 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | >=24.0.0<24.0.1 | |
IBM Business Automation Workflow | <24.0.0 | |
IBM Business Automation Workflow | >=24.0.0<24.0.1 | |
IBM Business Automation Workflow | <24.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54179 has been classified as a moderate severity vulnerability, allowing for cross-site scripting attacks.
To fix CVE-2024-54179, update IBM Business Automation Workflow or IBM Business Automation Workflow Enterprise Service Bus to a version later than 24.0.1.
CVE-2024-54179 affects users of IBM Business Automation Workflow versions 24.0.0 to 24.0.1 and IBM Business Automation Workflow Enterprise Service Bus versions 24.0.0 to 24.0.1.
CVE-2024-54179 enables authenticated users to conduct cross-site scripting (XSS) attacks by embedding arbitrary JavaScript code.
CVE-2024-54179 is a remote vulnerability, as it can be exploited through the web interface by authenticated users.