Improper Validation Vulnerability in IBM Robotic Process Automation
CVE-2024-49824

6.5MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 January 2025

Summary

The vulnerability in IBM Robotic Process Automation affects several versions, allowing an authenticated user to execute unauthorized actions as a privileged user. This is due to a failure in proper validation of client-side security enforcement measures, which could potentially enable malicious actors to bypass intended access controls. It is crucial for users of affected versions to implement necessary security patches and advisories provided by IBM to safeguard against this vulnerability.

Affected Version(s)

Robotic Process Automation 21.0.0 <= 21.0.7.18

Robotic Process Automation 23.0.0 <= 23.0.18

Robotic Process Automation for Cloud Pak 21.0.0 <= 21.0.7.18

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.