IBM Business Automation Workflow kuze kube 22.0.2 Web UI Ukubhalwa kwekhodi okweqa indawo

CVSS Meta Temp IsilinganisoIntengo yamanje ye-exploit (≈)CTI Inzalo Score
4.7$0-$5k0.00

Isifinyezoulwazi

Kutholakale ubuthakathaka obubizwa ngokuthi kuyinkinga ku IBM Business Automation Workflow kuze kube 22.0.2. Kuthinteka umsebenzi $software_function kwe-component Web UI. Ukuguqulwa kubangela uhlobo lwe Ukubhalwa kwekhodi okweqa indawo. Le buthakathaka ibizwa ngokuthi CVE-2023-24957. Kungenzeka ukuqalisa ukuhlasela ungasekho endaweni. I-exploit ayitholakali. Kuyacetyiswa ukuthi ingxenye ethintekayo ithuthukiswe. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

Iinkcukachaulwazi

Kutholakale ubuthakathaka obubizwa ngokuthi kuyinkinga ku IBM Business Automation Workflow kuze kube 22.0.2. Kuthinteka umsebenzi $software_function kwe-component Web UI. Ukuguqulwa kubangela uhlobo lwe Ukubhalwa kwekhodi okweqa indawo. Ukusebenzisa i-CWE ukumemezela inkinga kuholela ku-CWE-79. Lobu buthakathaka bakhishwa obala 2023-05-06. Isaziso sitholakala ukuthi singalayishwa ku-ibm.com.

Le buthakathaka ibizwa ngokuthi CVE-2023-24957. I-CVE yanikezwa ngo-2023-02-01. Kungenzeka ukuqalisa ukuhlasela ungasekho endaweni. Akukho mininingwane yezobuchwepheshe etholakalayo. Ukuduma kwalobu buthakathi kungaphansi kokujwayelekile. I-exploit ayitholakali. Okwamanje, intengo yamanje ye-exploit ingaba cishe USD $0-$5k ngalesi sikhathi.

Kuyacetyiswa ukuthi ingxenye ethintekayo ithuthukiswe.

Ubuthakathaka lolu lukhona futhi kwamanye ama-database okubuthakathaka: X-Force (246115). Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

Umkhiqizoulwazi

Uhlobo

Umkhiqizi

Ibizo

Inguqulo

Ilayisense

Iwebhusayithi

CPE 2.3ulwazi

CPE 2.2ulwazi

CVSSv4ulwazi

VulDB Umkhombandlela: 🔍
VulDB Ukuthembeka: 🔍

CVSSv3ulwazi

VulDB Ireyithingi yeMeta Base: 4.8
VulDB Meta Temp Isilinganiso: 4.7

VulDB Isilinganiso Esiyisisekelo: 3.5
VulDB Izinga Lesikhashana: 3.4
VulDB Umkhombandlela: 🔍
VulDB Ukuthembeka: 🔍

NVD Isilinganiso Esiyisisekelo: 5.4
NVD Umkhombandlela: 🔍

CNA Isilinganiso Esiyisisekelo: 5.4
CNA Umkhombandlela (IBM Corporation): 🔍

CVSSv2ulwazi

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
UmkhombandlelaUbunzimaUkufakazela ubuwenaUkuyimfihloUkuthembekaUkutholakala
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

VulDB Isilinganiso Esiyisisekelo: 🔍
VulDB Izinga Lesikhashana: 🔍
VulDB Ukuthembeka: 🔍

Ukusebenzisa ithuba lokungavikelekiulwazi

Ikilasi: Ukubhalwa kwekhodi okweqa indawo
CWE: CWE-79 / CWE-94 / CWE-74
CAPEC: 🔍
ATT&CK: 🔍

Okubambekayo: Hayi
Wendawo: Hayi
Kude: Yebo

Ukutholakala: 🔍
Isimo: Akuchazwanga

EPSS Score: 🔍
EPSS Percentile: 🔍

Ukukhula kwentengo: 🔍
Okwamanje ukuhlolwa kwentengo: 🔍

0-Dayvula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
Namuhlavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

Ulwazi lwezingoziulwazi

Intshisekelo: 🔍
Abadlali abasebenzayo: 🔍
AmaQembu e-APT asebenzayo: 🔍

Izinyathelo zokuvikelaulwazi

Isincomo: Buyisela phezulu
Isimo: 🔍

0-Suku Isikhathi: 🔍

Isikhathi somlandoulwazi

2023-02-01 🔍
2023-05-06 +93 Izinsuku 🔍
2023-05-06 +0 Izinsuku 🔍
2025-04-26 +721 Izinsuku 🔍

Imithomboulwazi

Umkhiqizi: ibm.com

Iseluleko: ibm.com
Isimo: Kuqinisekisiwe

CVE: CVE-2023-24957 (🔍)
GCVE (CVE): GCVE-0-2023-24957
GCVE (VulDB): GCVE-100-228165
X-Force: 246115

Ukungenaulwazi

Kudalwa: 2023-05-06 11:37
Ukuvuselelwa: 2025-04-26 22:53
Ukulungiswa: 2023-05-06 11:37 (52), 2025-01-29 17:48 (26), 2025-04-26 22:53 (3)
Kugcwele: 🔍
Cache ID: 253:5AE:103

Ingxoxo

Kuze kube manje akukabikho ukuphawula. Izilimi: nr + nd + en.

Ngiyacela ungene ngemvume ukuze ukwazi ukuphawula.

Do you know our Splunk app?

Download it now for free!