Lucene search

K
nvd[email protected]NVD:CVE-2024-31897
HistoryJul 08, 2024 - 3:15 a.m.

CVE-2024-31897

2024-07-0803:15:02
CWE-918
web.nvd.nist.gov
3
ibm
cloud pak
business automation
ssrf
vulnerable

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0

Percentile

13.4%

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 288178.

Affected configurations

Nvd
Node
ibmcloud_pak_for_business_automationRange18.0.018.0.2
OR
ibmcloud_pak_for_business_automationRange19.0.119.0.3
OR
ibmcloud_pak_for_business_automationRange20.0.120.0.3
OR
ibmcloud_pak_for_business_automationMatch21.0.1-
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_005
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_006
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_007
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_008
OR
ibmcloud_pak_for_business_automationMatch21.0.3-
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_005
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_006
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_007
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_008
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_009
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_010
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_011
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_012
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_013
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_014
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_015
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_016
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_017
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_018
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_019
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_020
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_021
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_022
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_023
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_024
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_025
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_026
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_028
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_029
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_030
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_031
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_032
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_033
OR
ibmcloud_pak_for_business_automationMatch22.0.1-
OR
ibmcloud_pak_for_business_automationMatch22.0.1interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch22.0.1interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch22.0.1interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch22.0.1interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch22.0.1interim_fix_005
OR
ibmcloud_pak_for_business_automationMatch22.0.1interim_fix_006
OR
ibmcloud_pak_for_business_automationMatch22.0.2-
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_005
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_006
OR
ibmcloud_pak_for_business_automationMatch23.0.1-
OR
ibmcloud_pak_for_business_automationMatch23.0.1interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch23.0.1interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch23.0.1interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch23.0.1interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch23.0.2-
OR
ibmcloud_pak_for_business_automationMatch23.0.2interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch23.0.2interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch23.0.2interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch23.0.2interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch23.0.2interim_fix_005
VendorProductVersionCPE
ibmcloud_pak_for_business_automation*cpe:2.3:a:ibm:cloud_pak_for_business_automation:*:*:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:-:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:interim_fix_001:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:interim_fix_002:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:interim_fix_003:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:interim_fix_004:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:interim_fix_005:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:interim_fix_006:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:interim_fix_007:*:*:*:*:*:*
ibmcloud_pak_for_business_automation21.0.1cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1:interim_fix_008:*:*:*:*:*:*
Rows per page:
1-10 of 681

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0

Percentile

13.4%

Related for NVD:CVE-2024-31897