8.8

CVE-2022-42438

IBM Cloud Pak for Multicloud Management Monitoring privilege escalation

IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths.  IBM X-Force ID:  238210.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version >= 2.0.0 < 2.3.0
   Linux ≫ Linux Kernel Version -
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version 2.3.0 Update fixpack2
   Linux ≫ Linux Kernel Version -
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version 2.3.0 Update fixpack3
   Linux ≫ Linux Kernel Version -
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version 2.3.0 Update fixpack4
   Linux ≫ Linux Kernel Version -
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version 2.3.0 Update fixpack5
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.406
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
IBM 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

https://exchange.xforce.ibmcloud.com/vulnerabilities/238210
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/6909427
Patch
Vendor Advisory