4.3

CVE-2024-31897

IBM Cloud Pak for Business Automation server-side request forgery

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.  IBM X-Force ID:  288178.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak For Business Automation Version >= 18.0.0 <= 18.0.2
Ibm ≫ Cloud Pak For Business Automation Version >= 19.0.1 <= 19.0.3
Ibm ≫ Cloud Pak For Business Automation Version >= 20.0.1 <= 20.0.3
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update -
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update interim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update interim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update interim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update interim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update -
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_009
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_010
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_011
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_012
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_013
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_014
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_015
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_016
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_017
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_018
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_019
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_020
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_021
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_022
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_023
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_024
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_025
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_026
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_028
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_029
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_030
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_031
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_032
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update interim_fix_033
Ibm ≫ Cloud Pak For Business Automation Version 22.0.1 Update -
Ibm ≫ Cloud Pak For Business Automation Version 22.0.1 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 22.0.1 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 22.0.1 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 22.0.1 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 22.0.1 Update interim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version 22.0.1 Update interim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version 22.0.2 Update -
Ibm ≫ Cloud Pak For Business Automation Version 22.0.2 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 22.0.2 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 22.0.2 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 22.0.2 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 22.0.2 Update interim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version 22.0.2 Update interim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version 23.0.1 Update -
Ibm ≫ Cloud Pak For Business Automation Version 23.0.1 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 23.0.1 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 23.0.1 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 23.0.1 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 23.0.2 Update -
Ibm ≫ Cloud Pak For Business Automation Version 23.0.2 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 23.0.2 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 23.0.2 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 23.0.2 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 23.0.2 Update interim_fix_005
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.211
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
IBM 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://exchange.xforce.ibmcloud.com/vulnerabilities/288178
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/7159332
Vendor Advisory