IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2
allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7182403 |
![]() ![]() |
History
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 05 Feb 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context. | |
Title | IBM Cloud Pak for Business Automation incorrect privilege assignment | |
Weaknesses | CWE-266 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-02-05T11:30:05.572Z
Updated: 2025-02-22T21:00:11.012Z
Reserved: 2024-10-14T12:05:24.914Z
Link: CVE-2024-49348

Updated: 2025-02-12T20:43:09.020Z

Status : Received
Published: 2025-02-05T12:15:28.570
Modified: 2025-02-05T12:15:28.570
Link: CVE-2024-49348

No data.