8.8
CVE-2023-38263
- EPSS 0.03%
- Veröffentlicht 02.02.2024 04:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:12
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM SOAR QRadar Plugin App improper access controls
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 260577.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Soar Qradar Plugin App Version >= 1.0 < 5.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.079 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@us.ibm.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.