Improper access control in Cloud Pak Foundational Services - CVE-2023-38367
Published: July 31, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to IBM Cloud Pak Foundational Services Identity Provider (idP) API allows CRUD Operations with an invalid token. A remote attacker can bypass implemented security restrictions to view, update, delete or create an IdP configuration.
Affected software
IBM Cloud Pak for Business Automation