4.3

CVE-2024-31897

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.  IBM X-Force ID:  288178.

Data is provided by the National Vulnerability Database (NVD)
IbmCloud Pak For Business Automation Version >= 18.0.0 <= 18.0.2
IbmCloud Pak For Business Automation Version >= 19.0.1 <= 19.0.3
IbmCloud Pak For Business Automation Version >= 20.0.1 <= 20.0.3
IbmCloud Pak For Business Automation Version21.0.1 Update-
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_008
IbmCloud Pak For Business Automation Version21.0.3 Update-
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_008
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_009
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_010
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_011
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_012
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_013
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_014
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_015
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_016
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_017
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_018
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_019
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_020
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_021
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_022
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_023
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_024
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_025
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_026
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_028
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_029
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_030
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_031
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_032
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_033
IbmCloud Pak For Business Automation Version22.0.1 Update-
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version22.0.2 Update-
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version23.0.1 Update-
IbmCloud Pak For Business Automation Version23.0.1 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version23.0.1 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version23.0.1 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version23.0.1 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version23.0.2 Update-
IbmCloud Pak For Business Automation Version23.0.2 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version23.0.2 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version23.0.2 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version23.0.2 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version23.0.2 Updateinterim_fix_005
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.218
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
psirt@us.ibm.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.