IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-52327 IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 29 Mar 2025 02:00:00 +0900

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Tue, 31 Dec 2024 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 30 Dec 2024 23:00:00 +0900

Type Values Removed Values Added
Description IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
Title IBM WebSphere Automation command injection
First Time appeared Ibm
Ibm websphere Automation
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:websphere_automation:1.7.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Automation
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-12-30T14:12:56.069Z

Reserved: 2024-11-30T14:47:55.533Z

Link: CVE-2024-54181

cve-icon Vulnrichment

Updated: 2024-12-30T14:12:52.124Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-30T14:15:05.867

Modified: 2025-03-28T16:32:40.990

Link: CVE-2024-54181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses