IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18
could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7177587 |
|
History
Mon, 18 Aug 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm robotic Process Automation For Cloud Pak
|
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm robotic Process Automation For Cloud Pak
|
Tue, 21 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 18 Jan 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement. | |
| Title | IBM Robotic Process Automation security bypass | |
| First Time appeared |
Ibm
Ibm robotic Process Automation |
|
| Weaknesses | CWE-602 | |
| CPEs | cpe:2.3:a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:21.0.7.17:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:23.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:robotic_process_automation:23.0.18:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm robotic Process Automation |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-01-18T15:11:58.522Z
Updated: 2025-01-21T20:58:13.548Z
Reserved: 2024-10-20T13:40:37.122Z
Link: CVE-2024-49824
Updated: 2025-01-21T20:57:57.736Z
Status : Analyzed
Published: 2025-01-18T16:15:39.183
Modified: 2025-08-18T17:56:28.077
Link: CVE-2024-49824
No data.