Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-54181
Disclosure Date: December 30, 2024 (last updated January 02, 2025)
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
0
Attacker Value
Unknown
CVE-2024-28764
Disclosure Date: May 01, 2024 (last updated May 02, 2024)
IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623.
0
Attacker Value
Unknown
CVE-2024-28775
Disclosure Date: May 01, 2024 (last updated May 02, 2024)
IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285648.
0
Attacker Value
Unknown
CVE-2022-43901
Disclosure Date: December 01, 2022 (last updated November 08, 2023)
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components. IBM X-Force ID: 240829.
0
Attacker Value
Unknown
CVE-2022-43900
Disclosure Date: December 01, 2022 (last updated November 08, 2023)
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827.
0
Attacker Value
Unknown
CVE-2022-22493
Disclosure Date: October 04, 2022 (last updated October 08, 2023)
IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.
0
Attacker Value
Unknown
CVE-2018-1885
Disclosure Date: April 08, 2019 (last updated November 27, 2024)
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request. IBM X-Force ID: 152020.
0
Attacker Value
Unknown
CVE-2018-1848
Disclosure Date: December 14, 2018 (last updated November 27, 2024)
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150947.
0