CVE Published: 04/09/2024 |
CVE Updated: 04/09/2024 |
CVE Year: 2024 Source: ibm |
Vendor: IBM |
Product: webMethods Integration Status : PUBLISHED
CVE-2024-45075 Description
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H