6.5
CVE-2024-49348
- EPSS 0.25%
- Veröffentlicht 05.02.2025 12:15:28
- Zuletzt bearbeitet 12.08.2025 16:36:42
- Erkennungen
IBM Cloud Pak for Business Automation incorrect privilege assignment
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak For Business Automation Version 18.0.0
Ibm ≫ Cloud Pak For Business Automation Version 18.0.1
Ibm ≫ Cloud Pak For Business Automation Version 18.0.2
Ibm ≫ Cloud Pak For Business Automation Version 19.0.1
Ibm ≫ Cloud Pak For Business Automation Version 19.0.2
Ibm ≫ Cloud Pak For Business Automation Version 19.0.3
Ibm ≫ Cloud Pak For Business Automation Version 20.0.1
Ibm ≫ Cloud Pak For Business Automation Version 20.0.2
Ibm ≫ Cloud Pak For Business Automation Version 20.0.3
Ibm ≫ Cloud Pak For Business Automation Version 21.0.1 Update -
Ibm ≫ Cloud Pak For Business Automation Version 21.0.2 Update -
Ibm ≫ Cloud Pak For Business Automation Version 21.0.3 Update -
Ibm ≫ Cloud Pak For Business Automation Version 22.0.1 Update -
Ibm ≫ Cloud Pak For Business Automation Version 22.0.2 Update -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.166 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| IBM | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
https://www.ibm.com/support/pages/node/7182403