4.3
CVE-2024-31897
- EPSS 0.07%
- Veröffentlicht 08.07.2024 03:15:02
- Zuletzt bearbeitet 21.11.2024 09:14:06
- Quelle psirt@us.ibm.com
- Teams Watchlist Login
- Unerledigt Login
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 288178.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak For Business Automation Version >= 18.0.0 <= 18.0.2
Ibm ≫ Cloud Pak For Business Automation Version >= 19.0.1 <= 19.0.3
Ibm ≫ Cloud Pak For Business Automation Version >= 20.0.1 <= 20.0.3
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Update-
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Update-
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_009
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_010
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_011
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_012
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_013
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_014
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_015
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_016
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_017
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_018
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_019
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_020
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_021
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_022
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_023
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_024
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_025
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_026
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_028
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_029
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_030
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_031
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_032
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_033
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Update-
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Update-
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version23.0.1 Update-
Ibm ≫ Cloud Pak For Business Automation Version23.0.1 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version23.0.1 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version23.0.1 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version23.0.1 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version23.0.2 Update-
Ibm ≫ Cloud Pak For Business Automation Version23.0.2 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version23.0.2 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version23.0.2 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version23.0.2 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version23.0.2 Updateinterim_fix_005
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.218 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
psirt@us.ibm.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.