CVE-2024-54181

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7179994 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:websphere_automation:1.7.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

28 Mar 2025, 16:32

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_automation:1.7.5:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7179994 - () https://www.ibm.com/support/pages/node/7179994 - Vendor Advisory
Summary
  • (es) IBM WebSphere Automation 1.7.5 podría permitir que un usuario remoto con privilegios, que tenga acceso autorizado a la interfaz de usuario de Swagger, ejecute código arbitrario. Mediante una entrada especialmente manipulada, el usuario podría aprovechar esta vulnerabilidad para ejecutar código arbitrario en el sistema.
First Time Ibm websphere Automation
Linux linux Kernel
Ibm
Linux

30 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-30 14:15

Updated : 2025-03-28 16:32


NVD link : CVE-2024-54181

Mitre link : CVE-2024-54181

CVE.ORG link : CVE-2024-54181


JSON object : View

Products Affected

ibm

  • websphere_automation

linux

  • linux_kernel
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')