Not a vulnerability - CVE-2024-6531

 

Not a vulnerability - CVE-2024-6531

Published: September 25, 2024 / Updated: December 16, 2025


Vulnerability identifier: #VU97689
CSH Severity: Medium
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-6531
CWE-ID:
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The reported issue was reviewed and determined not to constitute a security vulnerability.

Original description:

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data passed via an anchor element (<a>), when used for carousel navigation with a data-slide attribute. A remote attacker can execute arbitrary JavaScript code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Data Virtualization (DV) on Cloud Pak for Data (CPD)
Watson Query on Cloud Pak for Data
Storage Defender Copy Data Management
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
SOAR QRadar Plugin App
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Power Hardware Management Console (HMC)
IBM Qradar SIEM
Splunk Enterprise
Ubuntu
twitter-bootstrap3 (Ubuntu package)

How to mitigate CVE-2024-6531


Data Virtualization (DV) on Cloud Pak for Data (CPD) - addressed in versions 2.2.8, 3.1.0
Watson Query on Cloud Pak for Data - update to 2.2.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
Splunk Enterprise - addressed in versions 9.1.7, 9.2.4, 9.3.2
IBM Power Hardware Management Console (HMC) - update to 10.3.1060.0 SP1
Storage Defender Copy Data Management - update to 2.2.28.0
twitter-bootstrap3 (Ubuntu package) - addressed in versions 3.3.6+dfsg-1ubuntu0.1~esm1, 3.3.7+dfsg-2ubuntu0.1~esm1, 3.4.1+dfsg-1ubuntu0.1~esm1, 3.4.1+dfsg-3+deb12u1build0.24.04.1, 3.4.1+dfsg-3+deb12u1build0.24.10.1, 3.4.1+dfsg-3+deb12u1build0.25.04.1, 3.4.1+dfsg-2+deb11u2build0.22.04.1, 4.4.1+dfsg1-2ubuntu0.1~esm1, 4.6.0+dfsg1-4ubuntu0.1~esm1, 4.6.1+dfsg1-4+deb12u1build0.24.04.1, 4.6.1+dfsg1-4+deb12u1build0.24.10.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
SOAR QRadar Plugin App - update to 5.6.0

External References

Related Security Bulletins