IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7179994 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2024-12-30 14:15
Updated : 2025-03-28 16:32
NVD link : CVE-2024-54181
Mitre link : CVE-2024-54181
CVE.ORG link : CVE-2024-54181
JSON object : View
Products Affected
ibm
- websphere_automation
linux
- linux_kernel
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
