Information disclosure in IBM Cloud Pak for Business Automation - CVE-2023-50959
Published: April 5, 2024
Vulnerability identifier: #VU88172
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50959
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
IBM Business Automation Workflow
How to mitigate CVE-2023-50959
Install updates from vendor's website.
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
IBM Business Automation Workflow - addressed in versions 21.0.3 IF031, 23.0.2 IF003
IBM Business Automation Workflow - addressed in versions 21.0.3 IF031, 23.0.2 IF003