Improper access control in Cloud Pak Foundational Services - CVE-2023-38367

 

Improper access control in Cloud Pak Foundational Services - CVE-2023-38367

Published: July 31, 2023


Vulnerability identifier: #VU78760
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38367
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to IBM Cloud Pak Foundational Services Identity Provider (idP) API allows CRUD Operations with an invalid token. A remote attacker can bypass implemented security restrictions to view, update, delete or create an IdP configuration.


Affected software

Cloud Pak Foundational Services
IBM Cloud Pak for Business Automation

How to mitigate CVE-2023-38367

Install updates from vendor's website.

IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.23, 23.0.1.1

External References

Related Security Bulletins