CVE-2023-38367

MEDIUM

IBM Cloud Pak for Business Automation 18.0.0-22.0.2 - Unauthenticated CRUD Operations via Invalid Token

Title source: llm
STIX 2.1

Description

IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration. IBM X-Force ID: 261130.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7015271

Scores

CVSS v3 6.5
EPSS 0.0008
EPSS Percentile 23.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (12)
ibm/cloud_pak_for_business_automation 18.0.0
ibm/cloud_pak_for_business_automation 18.0.1
ibm/cloud_pak_for_business_automation 18.0.2
ibm/cloud_pak_for_business_automation 19.0.1
ibm/cloud_pak_for_business_automation 19.0.2
ibm/cloud_pak_for_business_automation 19.0.3
ibm/cloud_pak_for_business_automation 20.0.1
ibm/cloud_pak_for_business_automation 20.0.2
ibm/cloud_pak_for_business_automation 20.0.3
ibm/cloud_pak_for_business_automation 21.0.1 (8 CPE variants)
... and 2 more
Published Feb 29, 2024
Tracked Since Feb 18, 2026