5.4

CVE-2023-24957

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  IBM X-Force ID:  246115.

Data is provided by the National Vulnerability Database (NVD)
IbmBusiness Automation Workflow Version >= 19.0.0.1 <= 19.0.0.3
IbmBusiness Automation Workflow SwEditioncontainers Version >= 20.0.0.1 < 21.0.3
IbmBusiness Automation Workflow SwEditiontraditional Version >= 21.0.1 <= 21.0.3.1
IbmBusiness Automation Workflow SwEditioncontainers Version >= 22.0.1 < 22.0.2
IbmBusiness Automation Workflow Version18.0.0.0 SwEdition-
IbmBusiness Automation Workflow Version18.0.0.1 SwEdition-
IbmBusiness Automation Workflow Version18.0.0.2 SwEdition-
IbmBusiness Automation Workflow Version20.0.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version20.0.0.2 SwEditiontraditional
IbmBusiness Automation Workflow Version21.0.3 Update- SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif002 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif005 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif006 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif007 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif008 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif009 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif010 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif011 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif012 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif013 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif014 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif015 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif016 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif017 SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version22.0.2 SwEditiontraditional
IbmBusiness Automation Workflow Version22.0.2 Update- SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.2 Updateif001 SwEditioncontainers
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.269
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
psirt@us.ibm.com 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.