4

CVE-2023-23469

IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 244504.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmCloud Pak For Business Automation Version >= 18.0.0 <= 20.0.3
IbmCloud Pak For Business Automation Version21.0.1 Update-
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.2 Update-
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_0012
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_008
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_009
IbmCloud Pak For Business Automation Version21.0.3 Update-
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_008
IbmCloud Pak For Business Automation Version22.0.2 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.047
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
psirt@us.ibm.com 4 2.5 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-525 Use of Web Browser Cache Containing Sensitive Information

The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.