6.5
CVE-2023-38367
- EPSS 0.06%
- Published 29.02.2024 02:15:09
- Last modified 27.03.2025 15:15:46
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration. IBM X-Force ID: 261130.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak For Business Automation Version18.0.0
Ibm ≫ Cloud Pak For Business Automation Version18.0.1
Ibm ≫ Cloud Pak For Business Automation Version18.0.2
Ibm ≫ Cloud Pak For Business Automation Version19.0.1
Ibm ≫ Cloud Pak For Business Automation Version19.0.2
Ibm ≫ Cloud Pak For Business Automation Version19.0.3
Ibm ≫ Cloud Pak For Business Automation Version20.0.1
Ibm ≫ Cloud Pak For Business Automation Version20.0.2
Ibm ≫ Cloud Pak For Business Automation Version20.0.3
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Update-
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version21.0.1 Updateinterim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Update-
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_0012
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_009
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_010
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_011
Ibm ≫ Cloud Pak For Business Automation Version21.0.2 Updateinterim_fix_012
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Update-
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_009
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_010
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_011
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_012
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_013
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_014
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_015
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_016
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_017
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_018
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_019
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_020
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_021
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_022
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Update-
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version22.0.1 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Update-
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version22.0.2 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version23.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.189 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
psirt@us.ibm.com | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.