Insufficient Session Expiration in IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak - CVE-2024-49825
Published: April 16, 2025
Vulnerability identifier: #VU107493
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-49825
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user gain access to sensitive information.
The vulnerability exists due to application does not invalidate session after a logout. A remote authenticated user can impersonate another user on the system
Affected software
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2024-49825
Install updates from vendor's website.
IBM Robotic Process Automation - update to 23.0.20.1
Robotic Process Automation for Cloud Pak - update to 23.0.20.1
Robotic Process Automation for Cloud Pak - update to 23.0.20.1