6.5

CVE-2023-38367

IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration.  IBM X-Force ID:  261130.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmCloud Pak For Business Automation Version21.0.1 Update-
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.1 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.2 Update-
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_0012
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_008
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_009
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_010
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_011
IbmCloud Pak For Business Automation Version21.0.2 Updateinterim_fix_012
IbmCloud Pak For Business Automation Version21.0.3 Update-
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_008
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_009
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_010
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_011
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_012
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_013
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_014
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_015
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_016
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_017
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_018
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_019
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_020
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_021
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_022
IbmCloud Pak For Business Automation Version22.0.1 Update-
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version22.0.1 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version22.0.2 Update-
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version22.0.2 Updateinterim_fix_006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.189
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
psirt@us.ibm.com 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.