Not a vulnerability - CVE-2024-6531
Published: September 25, 2024 / Updated: December 16, 2025
Vulnerability details
The reported issue was reviewed and determined not to constitute a security vulnerability.
Original description:
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via an anchor element (<a>), when used for carousel navigation with a data-slide attribute. A remote attacker can execute arbitrary JavaScript code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Watson Query on Cloud Pak for Data
Storage Defender Copy Data Management
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
SOAR QRadar Plugin App
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Power Hardware Management Console (HMC)
IBM Qradar SIEM
Splunk Enterprise
Ubuntu
twitter-bootstrap3 (Ubuntu package)
How to mitigate CVE-2024-6531
Watson Query on Cloud Pak for Data - update to 2.2.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
Splunk Enterprise - addressed in versions 9.1.7, 9.2.4, 9.3.2
IBM Power Hardware Management Console (HMC) - update to 10.3.1060.0 SP1
Storage Defender Copy Data Management - update to 2.2.28.0
twitter-bootstrap3 (Ubuntu package) - addressed in versions 3.3.6+dfsg-1ubuntu0.1~esm1, 3.3.7+dfsg-2ubuntu0.1~esm1, 3.4.1+dfsg-1ubuntu0.1~esm1, 3.4.1+dfsg-3+deb12u1build0.24.04.1, 3.4.1+dfsg-3+deb12u1build0.24.10.1, 3.4.1+dfsg-3+deb12u1build0.25.04.1, 3.4.1+dfsg-2+deb11u2build0.22.04.1, 4.4.1+dfsg1-2ubuntu0.1~esm1, 4.6.0+dfsg1-4ubuntu0.1~esm1, 4.6.1+dfsg1-4+deb12u1build0.24.04.1, 4.6.1+dfsg1-4+deb12u1build0.24.10.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
SOAR QRadar Plugin App - update to 5.6.0
External References
Related Security Bulletins
- DISCARDED - Cross-site scripting in Bootstrap
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in IBM Data Virtualization on Cloud Pak for Data
- IBM Power Hardware Management Console (HMC) update for Node.js Bootstrap
- Multiple vulnerabilities in IBM SOAR QRadar Plugin App
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for Bootstrap
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- Ubuntu update for twitter-bootstrap3
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Storage Defender Copy Data Management