Incorrect Privilege Assignment in IBM Business Automation Workflow - CVE-2024-49348
Published: February 5, 2025
Vulnerability identifier: #VU103641
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-49348
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to modify data on the system.
The vulnerability exists due to IBM Business Automation Workflow allows restricting access to organizational data to valid contexts. A remote attacker can reassign tasks of type comment via API implicitly to gain access to user queries in an unexpected context.
Affected software
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Business Automation
How to mitigate CVE-2024-49348
Install updates from vendor's website.
IBM Business Automation Workflow - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1