PT-2025-2404 · Ibm · Ibm Automation Decision Services

Published

2025-01-26

·

Updated

2025-08-14

·

CVE-2024-31906

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM Automation Decision Services version 23.0.2
Description: The issue is related to the disclosure of information through browser caching. This can allow an attacker to gain unauthorized access to protected information. The problem arises because web pages can be stored locally and read by another user on the system.
Recommendations: For IBM Automation Decision Services version 23.0.2, consider clearing browser cache regularly to minimize the risk of information disclosure. As a temporary workaround, restrict access to sensitive information on shared systems until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01213
CVE-2024-31906

Affected Products

Ibm Automation Decision Services