8.8
CVE-2022-42438
- EPSS 0.32%
- Veröffentlicht 08.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:58
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Cloud Pak for Multicloud Management Monitoring privilege escalation
IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version >= 2.0.0 < 2.3.0
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version2.3.0
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version2.3.0 Updatefixpack2
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version2.3.0 Updatefixpack3
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version2.3.0 Updatefixpack4
Ibm ≫ Cloud Pak For Multicloud Management Monitoring Version2.3.0 Updatefixpack5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.548 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@us.ibm.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-425 Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.