cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-54181,https://securityvulnerability.io/vulnerability/CVE-2024-54181,Remote Code Execution Vulnerability in IBM WebSphere Automation,"IBM WebSphere Automation version 1.7.5 presents a significant security risk that enables a remote privileged user, granted access to the swagger UI, to execute arbitrary code. By utilizing specially crafted input, an attacker can exploit this vulnerability to gain control of the system, leading to potential data breaches or further compromise. Organizations using this version are advised to implement appropriate security measures and monitor for suspicious activities.",IBM,Websphere Automation,7.2,HIGH,0.0005200000014156103,false,false,false,false,false,false,false,2024-12-30T13:41:57.834Z,0 CVE-2024-28764,https://securityvulnerability.io/vulnerability/CVE-2024-28764,CSV Injection Vulnerability in IBM WebSphere Automation Could Lead to Arbitrary Command Execution,"IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623.",IBM,Websphere Automation,6.5,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-05-01T16:35:38.108Z,0 CVE-2024-28775,https://securityvulnerability.io/vulnerability/CVE-2024-28775,WebSphere Automation Vulnerable to Cross-Site Scripting,IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285648.,IBM,Websphere Automation,4.4,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-05-01T12:55:06.245Z,0 CVE-2022-43901,https://securityvulnerability.io/vulnerability/CVE-2022-43901,IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps information disclosure," IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components. IBM X-Force ID: 240829. ",IBM,Websphere Automation For Cloud Pak For Watson Aiops,5.7,MEDIUM,0.0004199999966658652,false,false,false,false,,false,false,2022-12-01T18:09:20.923Z,0 CVE-2022-43900,https://securityvulnerability.io/vulnerability/CVE-2022-43900,IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps security bypass," IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827. ",IBM,Websphere Automation For IBM Cloud Pak For Watson Aiops,5.3,MEDIUM,0.0004199999966658652,false,false,false,false,,false,false,2022-12-01T18:00:27.526Z,0 CVE-2022-22493,https://securityvulnerability.io/vulnerability/CVE-2022-22493,,"IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.",IBM,Websphere Automation For Cloud Pak For Watson Aiops,3.5,LOW,0.0007300000288523734,false,false,false,false,,false,false,2022-10-07T17:15:00.000Z,0