CVE-2024-38321

MEDIUM

IBM Business Automation Workflow <24.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations that could be read by an authenticated user. IBM X-Force ID: 284868.

Scores

CVSS v3 5.3
EPSS 0.0008
EPSS Percentile 22.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (10)
ibm/business_automation_workflow 20.0.0.1
ibm/business_automation_workflow 20.0.0.2
ibm/business_automation_workflow 21.0.2
ibm/business_automation_workflow 21.0.3 (22 CPE variants)
ibm/business_automation_workflow 22.0.1
ibm/business_automation_workflow 22.0.2 (2 CPE variants)
ibm/business_automation_workflow 23.0.1
ibm/business_automation_workflow 23.0.2
ibm/business_automation_workflow 19.0.0.1 - 19.0.0.3
ibm/business_automation_workflow 23.0.1 - 23.0.2
Published Aug 03, 2024
Tracked Since Feb 18, 2026