Known vulnerabilities in watsonx Code Assistant for Ansible

Software CPE: cpe:2.3:a:ibm_corporation:watsonx_code_assistant_for_ansible:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting watsonx Code Assistant for Ansible watsonx Code Assistant for Ansible is affected by 12 known vulnerabilities: 1 high, 5 medium, 6 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU105387 - Improper input validation
CVE-2025-27516
CWE-20 Low
No
No
5.1.3 06.03.2025 SB2025030628
SB2025031001
SB2025031002
and 83 more
#VU101972 - Security Features
CVE-2024-56326
CWE-254 Low
No
No
5.1.1 27.12.2024 SB2024122789
SB2024122790
SB2024122791
and 78 more
#VU101971 - Security Features
CVE-2024-56201
CWE-254 Low
No
No
5.1.1 27.12.2024 SB2024122789
SB2025010203
SB2025010322
and 62 more
#VU101032 - Command injection
CVE-2024-53899
CWE-77 Low
No
No
5.1.1 28.11.2024 SB2024112869
SB2024112872
SB2024112873
and 18 more
#VU100600 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-52304
CWE-444 Medium
No
No
5.1.1 19.11.2024 SB2024111901
SB2024111916
SB2024111917
and 19 more
#VU99567 - Resource exhaustion
CVE-2024-49767
CWE-400 Medium
No
No
5.1.1 31.10.2024 SB2024103173
SB2024103176
SB2024110601
and 30 more
#VU99566 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-49766
CWE-22 Medium
No
No
5.1.1 31.10.2024 SB2024103173
SB2024121313
SB2024121851
and 16 more
#VU99357 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-9287
CWE-78 Low
No
No
5.1.1 28.10.2024 SB2024102836
SB2024102838
SB20241101111
and 117 more
#VU95339 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-6345
CWE-94 High
No
No
5.1.1 05.08.2024 SB2024080590
SB2024080593
SB2024080594
and 159 more
#VU92262 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37891
CWE-200 Low
No
No
5.1.1 19.06.2024 SB2024061955
SB20240625146
SB2024062605
and 193 more
#VU77348 - Improper input validation
CVE-2023-32636
CWE-20 Medium
No
No
5.1.1 15.06.2023 SB2023041955
SB2023061510
SB2023080276
and 14 more
#VU75664 - Exposure of sensitive information to an unauthorized actor
CVE-2023-30861
CWE-200 Medium
No
No
5.0.3 02.05.2023 SB2023050221
SB2023052227
SB2023052228
and 44 more