4.9

CVE-2024-43188

IBM Business Automation Workflow 

22.0.2, 23.0.1, 23.0.2, and 24.0.0

could allow a privileged user to perform unauthorized activities due to improper client side validation.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmBusiness Automation Workflow SwEditiontraditional Version >= 18.0.0.1 <= 18.0.0.3
IbmBusiness Automation Workflow SwEditiontraditional Version >= 19.0.0.1 <= 19.0.0.3
IbmBusiness Automation Workflow SwEditiontraditional Version >= 21.0.1 <= 21.0.3.1
IbmBusiness Automation Workflow Version20.0.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version20.0.0.2 SwEditiontraditional
IbmBusiness Automation Workflow Version22.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version22.0.2 SwEditiontraditional
IbmBusiness Automation Workflow Version23.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version23.0.2 SwEditiontraditional
IbmBusiness Automation Workflow Version24.0.0 SwEditiontraditional
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.266
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
psirt@us.ibm.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CWE-602 Client-Side Enforcement of Server-Side Security

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.