Incorrect Privilege Assignment in IBM Business Automation Workflow - CVE-2024-49348

 

Incorrect Privilege Assignment in IBM Business Automation Workflow - CVE-2024-49348

Published: February 5, 2025


Vulnerability identifier: #VU103641
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-49348
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify data on the system.

The vulnerability exists due to IBM Business Automation Workflow allows restricting access to organizational data to valid contexts. A remote attacker can reassign tasks of type comment via API implicitly to gain access to user queries in an unexpected context.


Affected software

IBM Business Automation Workflow
IBM Cloud Pak for Business Automation

How to mitigate CVE-2024-49348

Install updates from vendor's website.

IBM Business Automation Workflow - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins