CVE Vulnerabilities

CVE-2024-22341

Improper Privilege Management

Published: Feb 22, 2025 | Modified: Sep 05, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privilege management.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Watson_query_with_cloud_pak_for_data Ibm 4.0 (including) 4.0.9 (including)
Watson_query_with_cloud_pak_for_data Ibm 4.5 (including) 4.5.3 (including)
Watson_query_with_cloud_pak_for_data Ibm 4.6 (including) 4.6.6 (including)
Watson_query_with_cloud_pak_for_data Ibm 4.7 (including) 4.7.4 (including)
Watson_query_with_cloud_pak_for_data Ibm 4.8 (including) 4.8.7 (including)

Potential Mitigations

References