VYPR

WebSphere Automation

by IBM

CVEs (3)

  • CVE-2024-54181Dec 30, 2024
    risk 0.00cvss epss 0.01

    IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.

  • CVE-2024-28764May 1, 2024
    risk 0.00cvss epss 0.00

    IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623.

  • CVE-2024-28775May 1, 2024
    risk 0.00cvss epss 0.00

    IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…