CVE-2024-49824
Estado: AnalizadaMedia (6.5)—
IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18
could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-602
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-49824",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-49824",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-21T20:58:08.747873Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:robotic_process_automation:21.0.7.17:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:robotic_process_automation:23.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:robotic_process_automation:23.0.18:*:*:*:*:*:*:*"
],
"vendor": "IBM",
"product": "Robotic Process Automation",
"versions": [
{
"status": "affected",
"version": "21.0.0",
"versionType": "semver",
"lessThanOrEqual": "21.0.7.18"
},
{
"status": "affected",
"version": "23.0.0",
"versionType": "semver",
"lessThanOrEqual": "23.0.18"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IBM",
"product": "Robotic Process Automation for Cloud Pak",
"versions": [
{
"status": "affected",
"version": "21.0.0",
"versionType": "semver",
"lessThanOrEqual": "21.0.7.18"
},
{
"status": "affected",
"version": "23.0.0",
"versionType": "semver",
"lessThanOrEqual": "23.0.18"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-01-18T16:15:39.183",
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7177587",
"tags": [
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"description": [
{
"lang": "en",
"value": "CWE-602"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and \n\nIBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18\n\ncould allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement."
},
{
"lang": "es",
"value": "IBM Robotic Process Automation 21.0.0 a 21.0.7.18 y 23.0.0 a 23.0.18 e IBM Robotic Process Automation for Cloud Pak 21.0.0 a 21.0.7.18 y 23.0.0 a 23.0.18 podría permitir que un usuario autenticado realice acciones no autorizadas como un usuario privilegiado debido a una validación incorrecta de la aplicación de la seguridad del lado del cliente."
}
],
"lastModified": "2026-06-17T08:00:29.680",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F17E6A3B-D7B8-4AAE-88B8-9BF14A81D538",
"versionEndExcluding": "21.0.7.19",
"versionStartIncluding": "21.0.0"
},
{
"criteria": "cpe:2.3:a:ibm:robotic_process_automation:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E64436B-5CE3-4DF8-9808-5BBD00D20506",
"versionEndExcluding": "23.0.19",
"versionStartIncluding": "23.0.0"
},
{
"criteria": "cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF26EA49-39D9-4943-9F1E-70DE28273743",
"versionEndExcluding": "21.0.7.19",
"versionStartIncluding": "21.0.0"
},
{
"criteria": "cpe:2.3:a:ibm:robotic_process_automation_for_cloud_pak:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02C6BCC6-21FF-4F31-ABB4-CF86020ABF3F",
"versionEndExcluding": "23.0.19",
"versionStartIncluding": "23.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}