CVE-2024-52365 MEDIUM

CVE-2024-52365: IBM Cloud Pak for Business Automation cross-site scripting

Vendor Ibm
Product Cloud Pak for Business Automation
Weakness CWE-79 · XSS
Published February 5, 2025
Last update February 22, 2025

CVSS base score

6.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Key dates

02Disclosure timeline

February 5, 2025 CVE published
February 22, 2025 Record updated