VYPR
Unrated severityNVD Advisory· Published Dec 30, 2024· Updated Dec 30, 2024

IBM WebSphere Automation command injection

CVE-2024-54181

Description

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • IBM/WebSphere Automationcpe-rescue2 versions
    cpe:2.3:a:ibm:websphere_automation:1.7.5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:websphere_automation:1.7.5:*:*:*:*:*:*:*range: 1.7.5
    • (no CPE)range: = 1.7.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.