Vulnerability Details
Basic Information
| Title | Security Bulletin: IBM watsonx Orchestrate Cartridge affected by vulnerability in IP |
|---|---|
| Type | ibm |
| Published | 2025-05-02T18:06:11 |
| Last Seen | 2025-05-02T18:56:38 |
| CVSS Score | 9.8 (CRITICAL) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2023-42282, CVE-2024-29415 |
|---|---|
| CWE | |
| Bulletin Family | software |
Description
IBM watsonx Orchestrate Cartridge contains a vulnerable version of IP
## Vulnerability Details
**CVEID:**CVE-2024-29415
**DESCRIPTION:** The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
**CWE:**CWE-918: Server-Side Request Forgery (SSRF)
**CVSS Source:** IBM X-Force
**CVSS Base score:** 7.5
**CVSS Vector:**(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
## Affected Products and Versions
Affected Product(s)| Version(s)
—|—
IBM watsonx Orchestrate with watsonx Assistant Cartridge| 4.8.4-4.8.5
IBM watsonx Orchestrate with watsonx Assistant Cartridge| 5.0.0-5.1.1
## Remediation/Fixes
Upgrade to IBM watsonx Orchestrate Cartridge 5.1.2
https://www.ibm.com/docs/en/watsonx/watson-orchestrate/current?topic=installing-watsonx-orchestrate-premises
## Workarounds and Mitigations
None
##
Impact Assessment
| Base Score | 9.8 |
|---|---|
| Severity | CRITICAL |