6.5

CVE-2024-38321

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations that could be read by an authenticated user.  IBM X-Force ID:  284868.

Data is provided by the National Vulnerability Database (NVD)
IbmBusiness Automation Workflow Version20.0.0.1 SwEditioncontainers
IbmBusiness Automation Workflow Version20.0.0.2 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.2 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Update- SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif002 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif005 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif006 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif007 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif008 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif009 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif010 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif011 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif012 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif013 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif014 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif015 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif016 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif017 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif028 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif029 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif030 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif031 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif032 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif033 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif034 SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.1 SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.2 SwEditioncontainers
IbmBusiness Automation Workflow Version23.0.1 SwEditioncontainers
IbmBusiness Automation Workflow Version23.0.2 SwEditioncontainers
IbmBusiness Automation Workflow SwEditiontraditional Version >= 19.0.0.1 <= 19.0.0.3
IbmBusiness Automation Workflow SwEditiontraditional Version >= 20.0.0.1 <= 20.0.0.2
IbmBusiness Automation Workflow SwEditiontraditional Version >= 21.0.1 <= 21.0.3.0
IbmBusiness Automation Workflow SwEditiontraditional Version >= 22.0.1 <= 22.0.2
IbmBusiness Automation Workflow SwEditiontraditional Version >= 23.0.1 <= 23.0.2
IbmBusiness Automation Workflow SwEditionenterprise_service_bus Version >= 23.0.1 <= 23.0.2
IbmBusiness Automation Workflow Version22.0.2 SwEditionenterprise_service_bus
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.231
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
psirt@us.ibm.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.