22.0.2, 23.0.1, 23.0.2, and 24.0.0
could allow a privileged user to perform unauthorized activities due to improper client side validation.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40098 | IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7168769 |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 29 Sep 2024 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:traditional:*:*:* cpe:2.3:a:ibm:business_automation_workflow:20.0.0.1:*:*:*:traditional:*:*:* cpe:2.3:a:ibm:business_automation_workflow:20.0.0.2:*:*:*:traditional:*:*:* cpe:2.3:a:ibm:business_automation_workflow:22.0.1:*:*:*:traditional:*:*:* cpe:2.3:a:ibm:business_automation_workflow:22.0.2:*:*:*:traditional:*:*:* cpe:2.3:a:ibm:business_automation_workflow:23.0.1:*:*:*:traditional:*:*:* cpe:2.3:a:ibm:business_automation_workflow:23.0.2:*:*:*:traditional:*:*:* cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:traditional:*:*:* |
Wed, 18 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Sep 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation. | |
| Title | IBM Business Automation Workflow improper input validation | |
| First Time appeared |
Ibm
Ibm business Automation Workflow |
|
| Weaknesses | CWE-602 | |
| CPEs | cpe:2.3:a:ibm:business_automation_workflow:22.0.2:*:*:*:-:*:*:* cpe:2.3:a:ibm:business_automation_workflow:23.0.1:*:*:*:-:*:*:* cpe:2.3:a:ibm:business_automation_workflow:23.0.2:*:*:*:-:*:*:* cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:-:*:*:* |
|
| Vendors & Products |
Ibm
Ibm business Automation Workflow |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-18T16:40:53.717Z
Reserved: 2024-08-07T13:29:34.029Z
Link: CVE-2024-43188
Updated: 2024-09-18T13:23:52.983Z
Status : Analyzed
Published: 2024-09-18T12:15:02.867
Modified: 2024-09-29T00:24:49.103
Link: CVE-2024-43188
No data.
OpenCVE Enrichment
No data.
EUVD