{"id":2132,"date":"2025-04-29T06:34:50","date_gmt":"2025-04-29T06:34:50","guid":{"rendered":"http:\/\/localhost\/?p=2132"},"modified":"2025-04-29T06:34:50","modified_gmt":"2025-04-29T06:34:50","slug":"security-bulletin-multiple-security-vulnerabilities-are-addressed-with-ibm-cloud-pak-for-business-au","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=2132","title":{"rendered":"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024."},"content":{"rendered":"<div class=\"vulnerability-details\">\n<h2>Vulnerability Details<\/h2>\n<div class=\"info-section\">\n<h3>Basic Information<\/h3>\n<table class=\"info-table\">\n<tr>\n<th>Title<\/th>\n<td>Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024.<\/td>\n<\/tr>\n<tr>\n<th>Type<\/th>\n<td>ibm<\/td>\n<\/tr>\n<tr>\n<th>Published<\/th>\n<td>2025-04-29T02:34:50<\/td>\n<\/tr>\n<tr>\n<th>Last Seen<\/th>\n<td>2025-04-29T11:05:59<\/td>\n<\/tr>\n<tr>\n<th>CVSS Score<\/th>\n<td style=\"color: #cc0000; font-weight: bold;\">9.8 (CRITICAL)<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"cvss-section\">\n<h3>CVSS v3 Details<\/h3>\n<table class=\"cvss-table\">\n<tr>\n<th>Attack Vector<\/th>\n<td>NETWORK<\/td>\n<\/tr>\n<tr>\n<th>Attack Complexity<\/th>\n<td>LOW<\/td>\n<\/tr>\n<tr>\n<th>Privileges Required<\/th>\n<td>NONE<\/td>\n<\/tr>\n<tr>\n<th>User Interaction<\/th>\n<td>NONE<\/td>\n<\/tr>\n<tr>\n<th>Scope<\/th>\n<td>UNCHANGED<\/td>\n<\/tr>\n<tr>\n<th>Confidentiality Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<tr>\n<th>Integrity Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<tr>\n<th>Availability Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"cve-section\">\n<h3>CVE Information<\/h3>\n<table class=\"cve-table\">\n<tr>\n<th>CVE IDs<\/th>\n<td>CVE-2017-11468, CVE-2017-18342, CVE-2017-18343, CVE-2020-1747, CVE-2023-2253, CVE-2023-2602, CVE-2023-2603, CVE-2023-26159, CVE-2023-33850, CVE-2023-44487, CVE-2023-4641, CVE-2023-50312, CVE-2023-51775, CVE-2024-1023, CVE-2024-20918, CVE-2024-20919, CVE-2024-20921, CVE-2024-20926, CVE-2024-20945, CVE-2024-20952, CVE-2024-22257, CVE-2024-22259, CVE-2024-22353, CVE-2024-25710, CVE-2024-26308, CVE-2024-27270, CVE-2024-28849, CVE-2024-29041<\/td>\n<\/tr>\n<tr>\n<th>CWE<\/th>\n<td><\/td>\n<\/tr>\n<tr>\n<th>Bulletin Family<\/th>\n<td>software<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"description-section\">\n<h3>Description<\/h3>\n<div class=\"description-content\">\n            ## Summary<\/p>\n<p>In addition to OS level package updates, multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation 21.0.3-IF032 and 23.0.2-IF004.<\/p>\n<p>## Vulnerability Details<\/p>\n<p>**CVEID:**CVE-2024-22353<br \/>\n**DESCRIPTION:** IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 280400.<br \/>\n**CWE:**CWE-770: Allocation of Resources Without Limits or Throttling<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.9<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2024-28849<br \/>\n**DESCRIPTION:** Node.js follow-redirects module could allow a remote authenticated attacker to obtain sensitive information, caused by the leakage of credentials when clearing authorization header during cross-domain redirect, but keeping the proxy-authentication header. An attacker could exploit this vulnerability to obtain credentials and other sensitive information.<br \/>\n**CWE:**CWE-200: Exposure of Sensitive Information to an Unauthorized Actor<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 6.5<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2023-26159<br \/>\n**DESCRIPTION:** follow-redirects could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted URL to redirect a victim to arbitrary Web sites.<br \/>\n**CWE:**CWE-601: URL Redirection to Untrusted Site (&#8216;Open Redirect&#8217;)<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 6.1<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-29041<br \/>\n**DESCRIPTION:** Express.js Express could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted URL to redirect a victim to arbitrary Web sites.<br \/>\n**CWE:**CWE-601: URL Redirection to Untrusted Site (&#8216;Open Redirect&#8217;)<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 6.1<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2023-44487<br \/>\n**DESCRIPTION:** Multiple vendors are vulnerable to a denial of service, caused by a flaw in handling multiplexed streams in the HTTP\/2 protocol. By sending numerous HTTP\/2 requests and RST_STREAM frames over multiple streams, a remote attacker could exploit this vulnerability to cause a denial of service due to server resource consumption.<br \/>\n**CWE:**CWE-400: Uncontrolled Resource Consumption<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 7.5<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2023-2253<br \/>\n**DESCRIPTION:** Distribution is vulnerable to a denial of service, caused by improper input validation by the \/v2\/_catalog endpoint. By sending a specially crafted \/v2\/_catalog API endpoint request request, a remote attacker could exploit this vulnerability to cause a denial of service condition.<br \/>\n**CWE:**CWE-20: Improper Input Validation<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 7.5<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2017-11468<br \/>\n**DESCRIPTION:** Docker Registry is vulnerable to a denial of service, caused by the failure to restrict content sizes. An attacker could exploit this vulnerability to cause memory consumption.<br \/>\n**CWE:**CWE-399: Resource Management Errors<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.3<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L)  <\/p>\n<p>**CVEID:**CVE-2023-2602<br \/>\n**DESCRIPTION:** libcap is vulnerable to a denial of service, caused by a memory leak flaw in the error handling in the __wrap_pthread_create() function. By sending a specially crafted request, a remote attacker could exploit this vulnerability to exhaust the process memory, and results in a denial of service condition.<br \/>\n**CWE:**CWE-401: Missing Release of Memory after Effective Lifetime<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 0<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2023-2603<br \/>\n**DESCRIPTION:** libcap could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the _libcap_strdup() function. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.<br \/>\n**CWE:**CWE-190: Integer Overflow or Wraparound<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.6<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L)  <\/p>\n<p>**CVEID:**CVE-2023-51775<br \/>\n**DESCRIPTION:** jose4j is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted p2c value, a remote attacker could exploit this vulnerability to cause a denial of service condition.<br \/>\n**CWE:**CWE-20: Improper Input Validation<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 7.5<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2017-18342<br \/>\n**DESCRIPTION:** PyYAML could allow a remote attacker to execute arbitrary code on the system, caused by the failure to use yaml.safe_load in the yaml.load() API. An attacker could exploit this vulnerability to execute arbitrary code on the system.<br \/>\n**CWE:**CWE-94: Improper Control of Generation of Code (&#8216;Code Injection&#8217;)<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 9.8<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H)  <\/p>\n<p>**CVEID:**CVE-2017-18343<br \/>\n**DESCRIPTION:** ** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a \/_debugbar\/open?op=get URI. NOTE: the vendor&#8217;s position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar.<br \/>\n**CWE:**CWE-79: Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;)<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 0<br \/>\n**CVSS Vector:**  <\/p>\n<p>**CVEID:**CVE-2020-1747<br \/>\n**DESCRIPTION:** PyYAML could allow a remote attacker to execute arbitrary code on the system, caused by an error when processing untrusted YAML files through the full_load method or with the FullLoader loader. By abusing the python\/object\/new constructor, an attacker could exploit this vulnerability to execute arbitrary code on the system.<br \/>\n**CWE:**CWE-94: Improper Control of Generation of Code (&#8216;Code Injection&#8217;)<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 9.8<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H)  <\/p>\n<p>**CVEID:**CVE-2024-22257<br \/>\n**DESCRIPTION:** VMware Tanzu Spring Security could allow a remote attacker to bypass security restrictions, caused by a broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter. By sending a direct request, an attacker could exploit this vulnerability to bypass access restrictions.<br \/>\n**CWE:**CWE-287: Improper Authentication<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 8.2<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-22259<br \/>\n**DESCRIPTION:** VMware Tanzu Spring Framework could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in UriComponentsBuilder. An attacker could exploit this vulnerability using a specially-crafted URL to redirect a victim to arbitrary Web sites.<br \/>\n**CWE:**CWE-601: URL Redirection to Untrusted Site (&#8216;Open Redirect&#8217;)<br \/>\n**CVSS Source:** CVE.org<br \/>\n**CVSS Base score:** 8.1<br \/>\n**CVSS Vector:**(CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-20952<br \/>\n**DESCRIPTION:** An unspecified vulnerability in Java SE related to the Security component could allow a remote attacker to cause high confidentiality impact and high integrity impact.<br \/>\n**CWE:**CWE-416: Use After Free<br \/>\n**CVSS Source:** CVE.org<br \/>\n**CVSS Base score:** 7.4<br \/>\n**CVSS Vector:**(CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-20918<br \/>\n**DESCRIPTION:** An unspecified vulnerability in Java SE related to the VM component could allow a remote attacker to cause high confidentiality impact and high integrity impact.<br \/>\n**CWE:**CWE-20: Improper Input Validation<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 7.4<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-20921<br \/>\n**DESCRIPTION:** An unspecified vulnerability in Java SE related to the VM component could allow a remote attacker to cause high confidentiality impact.<br \/>\n**CWE:**CWE-20: Improper Input Validation<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.9<br \/>\n**CVSS Vector:**  <\/p>\n<p>**CVEID:**CVE-2024-20919<br \/>\n**DESCRIPTION:** An unspecified vulnerability in Java SE related to the VM component could allow a remote attacker to cause high integrity impact.<br \/>\n**CWE:**CWE-20: Improper Input Validation<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 4.7<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:L\/AC:H\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-20926<br \/>\n**DESCRIPTION:** An unspecified vulnerability in Java SE related to the Scripting component could allow a remote attacker to cause high confidentiality impact.<br \/>\n**CWE:**CWE-20: Improper Input Validation<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.9<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-20945<br \/>\n**DESCRIPTION:** An unspecified vulnerability in Java SE related to the VM component could allow a local authenticated attacker to cause high confidentiality impact.<br \/>\n**CWE:**CWE-20: Improper Input Validation<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 4.7<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:L\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2023-33850<br \/>\n**DESCRIPTION:** IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.<br \/>\n**CWE:**CWE-203: Observable Discrepancy<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.9<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-1023<br \/>\n**DESCRIPTION:** Eclipse Vert.x is vulnerable to a denial of service, caused by a memory leak due to the use of Netty FastThreadLocal data structures. By persuading to open a specially crafted content, a remote attacker could exploit this vulnerability to cause a denial of service condition.<br \/>\n**CWE:**CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer<br \/>\n**CVSS Source:** CVE.org<br \/>\n**CVSS Base score:** 6.5<br \/>\n**CVSS Vector:**(CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2023-4641<br \/>\n**DESCRIPTION:** shadow-maint shadow-utils could allow a local authenticated attacker to obtain sensitive information, caused by failing to clean the buffer used to store password information. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain password information, and use this information to launch further attacks against the affected system.<br \/>\n**CWE:**CWE-303: Incorrect Implementation of Authentication Algorithm<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 4.7<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:L\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-26308<br \/>\n**DESCRIPTION:** Apache Commons Compress is vulnerable to a denial of service, caused by an out of memory error. By persuading a victim to open a specially crafted Pack200 file, a remote attacker could exploit this vulnerability to cause a denial of service condition.<br \/>\n**CWE:**CWE-770: Allocation of Resources Without Limits or Throttling<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.5<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:L\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2024-25710<br \/>\n**DESCRIPTION:** Apache Commons Compress is vulnerable to a denial of service, caused by an infinite loop flaw. By persuading a victim to open a specially crafted DUMP file, a remote attacker could exploit this vulnerability to cause a denial of service condition.<br \/>\n**CWE:**CWE-835: Loop with Unreachable Exit Condition (&#8216;Infinite Loop&#8217;)<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.5<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:L\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2023-50312<br \/>\n**DESCRIPTION:** IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.<br \/>\n**CWE:**CWE-327: Use of a Broken or Risky Cryptographic Algorithm<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 5.3<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:A\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2024-27270<br \/>\n**DESCRIPTION:** IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in a specially crafted URI. IBM X-Force ID: 284576.<br \/>\n**CWE:**CWE-79: Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;)<br \/>\n**CVSS Source:** IBM X-Force<br \/>\n**CVSS Base score:** 4.7<br \/>\n**CVSS Vector:**(CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N)<\/p>\n<p>## Affected Products and Versions<\/p>\n<p>Affected Product(s) | Version(s) | Status<br \/>\n&#8212;|&#8212;|&#8212;<br \/>\nIBM Cloud Pak for Business Automation | V23.0.2 &#8211; V23.0.2-IF003 | Affected<br \/>\nIBM Cloud Pak for Business Automation | V23.0.1 all fixes<br \/>\nV22.0.2 all fixes<br \/>\nV22.0.1 all fixes | Affected<br \/>\nIBM Cloud Pak for Business Automation | V21.0.3 &#8211; V21.0.3-IF031 | Affected<br \/>\nIBM Cloud Pak for Business Automation | V21.0.1 all fixes<br \/>\nV20.0.1 &#8211; V20.0.3<br \/>\nV19.0.1 &#8211; V19.0.3<br \/>\nV18.0.0 &#8211; V18.0.2 | Affected  <\/p>\n<p>## Remediation\/Fixes<\/p>\n<p>Affected Product(s) | Version(s) | Remediation \/ Fix<br \/>\n&#8212;|&#8212;|&#8212;<br \/>\nIBM Cloud Pak for Business Automation | V23.0.2 &#8211; V23.0.2-IF003 | Apply security fix 23.0.2-IF004<br \/>\nIBM Cloud Pak for Business Automation | V23.0.1 all fixes<br \/>\nV22.0.2 all fixes | Upgrade and apply security fix 23.0.2-IF004<br \/>\nIBM Cloud Pak for Business Automation | V21.0.3 &#8211; V21.0.3-IF031 | Apply security fix 21.0.3-IF032 or upgrade to 23.0.2-IF004<br \/>\nIBM Cloud Pak for Business Automation | V21.0.1 all fixes<br \/>\nV20.0.1 &#8211; V20.0.3<br \/>\nV19.0.1 &#8211; V19.0.3<br \/>\nV18.0.0 &#8211; V18.0.2 | Upgrade to 21.0.3-IF032 or 23.0.2-IF004  <\/p>\n<p>Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components. The CVE in this bulletin are specifically addressed by<\/p>\n<p>**CVE** | **Component**<br \/>\n&#8212;|&#8212;<br \/>\nCVE-2017-11468 | User Management Service Component<br \/>\nCVE-2017-18342 | Demo Pattern<br \/>\nCVE-2017-18343 | Demo Pattern<br \/>\nCVE-2020-1747 | Demo Pattern<br \/>\nCVE-2023-2253 | User Management Service Component<br \/>\nCVE-2023-2602 | User Management Service Component<br \/>\nCVE-2023-2603 | User Management Service Component<br \/>\nCVE-2023-26159 | Business Automation Insights Component<br \/>\nCVE-2023-33850 | Operational Decision Manager Component<br \/>\nCVE-2023-44487 | User Management Service Component<br \/>\nCVE-2023-4641 | Automation Decision Services<br \/>\nCVE-2023-50312 | Base Images<br \/>\nCVE-2023-51775 | Operational Decision Manager Component<br \/>\nCVE-2024-1023 | Business Automation Insights Core<br \/>\nCVE-2024-20918 | Operational Decision Manager Component<br \/>\nCVE-2024-20919 | Operational Decision Manager Component<br \/>\nCVE-2024-20921 | Operational Decision Manager Component<br \/>\nCVE-2024-20926 | Operational Decision Manager Component<br \/>\nCVE-2024-20945 | Operational Decision Manager Component<br \/>\nCVE-2024-20952  | Operational Decision Manager Component<br \/>\nCVE-2024-22257 | Automation Decision Services<br \/>\nCVE-2024-22259 | Automation Decision Services<br \/>\nCVE-2024-22353 | Base Images<br \/>\nCVE-2024-25710 | Automation Decision Services<br \/>\nCVE-2024-26308 | Automation Decision Services<br \/>\nCVE-2024-27270 | Base Images<br \/>\nCVE-2024-28849 | Business Automation Application Component<br \/>\nCVE-2024-28849 | Business Automation Insights Core<br \/>\nCVE-2024-29041 | Business Automation Insights Core  <\/p>\n<p>## Workarounds and Mitigations<\/p>\n<p>None<\/p>\n<p>##\n        <\/p><\/div>\n<\/p><\/div>\n<div class=\"impact-section\">\n<h3>Impact Assessment<\/h3>\n<table class=\"impact-table\">\n<tr>\n<th>Base Score<\/th>\n<td>9.8<\/td>\n<\/tr>\n<tr>\n<th>Severity<\/th>\n<td style=\"color: #cc0000;\">CRITICAL<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"source-link\">\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7150051\" target=\"_blank\">View full CVE details<\/a><\/p>\n<\/p><\/div>\n<\/div>\n<style>\n.vulnerability-details {\n    font-family: Arial, sans-serif;\n    max-width: 1200px;\n    margin: 0 auto;\n    padding: 20px;\n}<\/p>\n<p>.info-section, .cvss-section, .cve-section, .description-section, .impact-section {\n    margin-bottom: 30px;\n    background: #f8f9fa;\n    padding: 20px;\n    border-radius: 8px;\n    box-shadow: 0 2px 4px rgba(0,0,0,0.1);\n}<\/p>\n<p>h2 {\n    color: #2c3e50;\n    border-bottom: 2px solid #3498db;\n    padding-bottom: 10px;\n    margin-bottom: 20px;\n}<\/p>\n<p>h3 {\n    color: #34495e;\n    margin-bottom: 15px;\n}<\/p>\n<p>.info-table, .cvss-table, .cve-table, .impact-table {\n    width: 100%;\n    border-collapse: collapse;\n    margin-bottom: 20px;\n}<\/p>\n<p>.info-table th, .cvss-table th, .cve-table th, .impact-table th {\n    background: #e9ecef;\n    padding: 12px;\n    text-align: left;\n    width: 200px;\n}<\/p>\n<p>.info-table td, .cvss-table td, .cve-table td, .impact-table td {\n    padding: 12px;\n    border-bottom: 1px solid #dee2e6;\n}<\/p>\n<p>.description-content {\n    line-height: 1.6;\n    color: #2c3e50;\n}<\/p>\n<p>.source-link {\n    text-align: center;\n    margin-top: 30px;\n}<\/p>\n<p>.source-link a {\n    display: inline-block;\n    padding: 10px 20px;\n    background: #3498db;\n    color: white;\n    text-decoration: none;\n    border-radius: 5px;\n    transition: background 0.3s;\n}<\/p>\n<p>.source-link a:hover {\n    background: #2980b9;\n}\n<\/style>\n","protected":false},"excerpt":{"rendered":"<p>Vulnerability Details Basic Information Title Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. Type ibm&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[9,6,8,35,12,76,13,7,11,5],"class_list":["post-2132","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-critical","tag-cve","tag-cvss","tag-cvss-98","tag-exploit","tag-ibm","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=2132\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. - zero redgem\" \/>\n<meta property=\"og:description\" content=\"Vulnerability Details Basic Information Title Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. Type ibm...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=2132\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-29T06:34:50+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2132#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2132\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024.\",\"datePublished\":\"2025-04-29T06:34:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2132\"},\"wordCount\":2621,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.8\",\"exploit\",\"ibm\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=2132#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2132\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2132\",\"name\":\"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-04-29T06:34:50+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2132#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=2132\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2132#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=2132","og_locale":"en_US","og_type":"article","og_title":"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. - zero redgem","og_description":"Vulnerability Details Basic Information Title Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. Type ibm...","og_url":"https:\/\/zero.redgem.net\/?p=2132","og_site_name":"zero redgem","article_published_time":"2025-04-29T06:34:50+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=2132#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=2132"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024.","datePublished":"2025-04-29T06:34:50+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=2132"},"wordCount":2621,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.8","exploit","ibm","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=2132#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=2132","url":"https:\/\/zero.redgem.net\/?p=2132","name":"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024. - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-04-29T06:34:50+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=2132#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=2132"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=2132#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation Fixes for April 2024."}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/2132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2132"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/2132\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}