8.8

CVE-2022-42438

IBM Cloud Pak for Multicloud Management Monitoring privilege escalation

IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths.  IBM X-Force ID:  238210.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmCloud Pak For Multicloud Management Monitoring Version >= 2.0.0 < 2.3.0
   LinuxLinux Kernel Version-
IbmCloud Pak For Multicloud Management Monitoring Version2.3.0 Updatefixpack2
   LinuxLinux Kernel Version-
IbmCloud Pak For Multicloud Management Monitoring Version2.3.0 Updatefixpack3
   LinuxLinux Kernel Version-
IbmCloud Pak For Multicloud Management Monitoring Version2.3.0 Updatefixpack4
   LinuxLinux Kernel Version-
IbmCloud Pak For Multicloud Management Monitoring Version2.3.0 Updatefixpack5
   LinuxLinux Kernel Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.548
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@us.ibm.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.