First published: Mon Dec 30 2024(Updated: )
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Automation | <=1.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54181 is considered a high severity vulnerability due to the potential for remote code execution by authorized users.
To mitigate CVE-2024-54181, upgrade IBM WebSphere Automation to the latest version that addresses this vulnerability.
All users of IBM WebSphere Automation version 1.7.5 are affected by CVE-2024-54181 if they have access to the swagger UI.
CVE-2024-54181 allows for remote execution of arbitrary code by a privileged user through specially crafted input.
Yes, exploitation of CVE-2024-54181 requires authentication as it targets remote privileged users with access to the swagger UI.