Improper access control in Lenovo XClarity Controller (XCC) - CVE-2023-0683
Published: March 15, 2023
Vulnerability identifier: #VU73737
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0683
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the API. A remote user can send a specially crafted request to the API and gain unauthorized access to the application.
Affected software
Lenovo XClarity Controller (XCC)
IBM Cloud Pak System
IBM Cloud Pak System
How to mitigate CVE-2023-0683
Install updates from vendor's website.
IBM Cloud Pak System - update to 2.3.4.0