CVE-2024-45075

Published Sep 4, 2024

Last updated 2 months ago

Overview

Description
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.
Source
psirt@us.ibm.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-Other
psirt@us.ibm.com
CWE-308

Social media

Hype score
Not currently trending

Configurations