IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18
could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7177587 |
![]() ![]() |
History
Tue, 21 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 18 Jan 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement. | |
Title | IBM Robotic Process Automation security bypass | |
First Time appeared |
Ibm
Ibm robotic Process Automation |
|
Weaknesses | CWE-602 | |
CPEs | cpe:2.3:a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:21.0.7.17:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:23.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:23.0.18:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm robotic Process Automation |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-01-21T20:58:13.548Z
Reserved: 2024-10-20T13:40:37.122Z
Link: CVE-2024-49824

Updated: 2025-01-21T20:57:57.736Z

Status : Received
Published: 2025-01-18T16:15:39.183
Modified: 2025-01-18T16:15:39.183
Link: CVE-2024-49824

No data.