CVE-2024-38321

MEDIUM

IBM Business Automation Workflow <24.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations that could be read by an authenticated user. IBM X-Force ID: 284868.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7162334

Scores

CVSS v3 5.3
EPSS 0.0042
EPSS Percentile 33.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (10)
ibm/business_automation_workflow 20.0.0.1
ibm/business_automation_workflow 20.0.0.2
ibm/business_automation_workflow 21.0.2
ibm/business_automation_workflow 21.0.3 (22 CPE variants)
ibm/business_automation_workflow 22.0.1
ibm/business_automation_workflow 22.0.2 (2 CPE variants)
ibm/business_automation_workflow 23.0.1
ibm/business_automation_workflow 23.0.2
ibm/business_automation_workflow 19.0.0.1 - 19.0.0.3
ibm/business_automation_workflow 23.0.1 - 23.0.2
Published Aug 03, 2024
Tracked Since Feb 18, 2026