Cross-Site Scripting Vulnerability in IBM Business Automation Workflow
CVE-2024-54179

5.4MEDIUM

Key Information:

Summary

IBM Business Automation Workflow and its Enterprise Service Bus versions 24.0.0 and 24.0.1 are susceptible to a cross-site scripting flaw. This security issue permits an authenticated user to inject arbitrary JavaScript code within the Web UI, compromising the intended functionality. The potential outcomes include unauthorized access to sensitive data and credential disclosure during active sessions, making it crucial for users to ensure proper remediation.

Affected Version(s)

Business Automation Workflow 24.0.0, 24.0.1

Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.