PT-2024-33479 · Ibm · Ibm Watson Studio Local

Published

2024-10-15

·

Updated

2024-11-08

·

CVE-2024-49340

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Watson Studio Local version 1.2.3
Description The issue is related to a cross-site request forgery vulnerability, which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. This can lead to hijacked user sessions.
Recommendations For IBM Watson Studio Local version 1.2.3, upgrade the affected component immediately to mitigate the risk. As a temporary workaround, consider restricting access to sensitive actions that can be performed by the application to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-49340

Affected Products

Ibm Watson Studio Local