CVE-2024-54181
- EPSS 0.71%
- Published 30.12.2024 14:15:05
- Last modified 28.03.2025 16:32:40
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the sys...
CVE-2024-28764
- EPSS 0.07%
- Published 01.05.2024 17:15:31
- Last modified 11.04.2025 14:46:50
IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID:...
CVE-2024-28775
- EPSS 0.11%
- Published 01.05.2024 13:15:51
- Last modified 11.04.2025 14:09:38
IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru...