PT-2024-24272 · Ibm · Ibm Cloud Pak For Business Automation

Published

2024-07-07

·

Updated

2024-07-11

·

CVE-2024-31897

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak for Business Automation versions 18.0.0 through 23.0.2
Description The issue allows an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. This is due to a server-side request forgery (SSRF) vulnerability.
Recommendations For IBM Cloud Pak for Business Automation versions 18.0.0 through 23.0.2, apply the necessary patches or updates to resolve the server-side request forgery (SSRF) vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to sensitive network resources to minimize the risk of exploitation.

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-31897

Affected Products

Ibm Cloud Pak For Business Automation