CVE-2024-22341

EUVD-2024-19902
IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privilege management.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
ibmCNA
5.3 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
ibmwatson_query_with_cloud_pak_for_data
4.0 ≤
𝑥
≤ 4.0.9
ibmwatson_query_with_cloud_pak_for_data
4.5 ≤
𝑥
≤ 4.5.3
ibmwatson_query_with_cloud_pak_for_data
4.6 ≤
𝑥
≤ 4.6.6
ibmwatson_query_with_cloud_pak_for_data
4.7 ≤
𝑥
≤ 4.7.4
ibmwatson_query_with_cloud_pak_for_data
4.8 ≤
𝑥
≤ 4.8.7
𝑥
= Vulnerable software versions