CVE-2023-40691

MEDIUM

IBM Cloud Pak for Business Automation <22.0.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 may reveal sensitive information contained in application configuration to developer and administrator users. IBM X-Force ID: 264805.

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7096365

Scores

CVSS v3 4.9
EPSS 0.0005
EPSS Percentile 15.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (10)
ibm/cloud_pak_for_business_automation 18.0.0
ibm/cloud_pak_for_business_automation 18.0.2
ibm/cloud_pak_for_business_automation 19.0.1
ibm/cloud_pak_for_business_automation 19.0.3
ibm/cloud_pak_for_business_automation 20.0.1
ibm/cloud_pak_for_business_automation 20.0.3
ibm/cloud_pak_for_business_automation 21.0.1 (9 CPE variants)
ibm/cloud_pak_for_business_automation 21.0.3 (27 CPE variants)
ibm/cloud_pak_for_business_automation 22.0.2 (7 CPE variants)
ibm/cloud_pak_for_business_automation 23.0.1
Published Dec 18, 2023
Tracked Since Feb 18, 2026