Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38367


IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration. IBM X-Force ID: 261130.


Published

2024-02-29T02:15:09.120

Last Modified

2025-03-27T15:15:46.923

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm cloud_pak_for_business_automation 18.0.0 Yes
Application ibm cloud_pak_for_business_automation 18.0.1 Yes
Application ibm cloud_pak_for_business_automation 18.0.2 Yes
Application ibm cloud_pak_for_business_automation 19.0.1 Yes
Application ibm cloud_pak_for_business_automation 19.0.2 Yes
Application ibm cloud_pak_for_business_automation 19.0.3 Yes
Application ibm cloud_pak_for_business_automation 20.0.1 Yes
Application ibm cloud_pak_for_business_automation 20.0.2 Yes
Application ibm cloud_pak_for_business_automation 20.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.1 Yes
Application ibm cloud_pak_for_business_automation 21.0.1 Yes
Application ibm cloud_pak_for_business_automation 21.0.1 Yes
Application ibm cloud_pak_for_business_automation 21.0.1 Yes
Application ibm cloud_pak_for_business_automation 21.0.1 Yes
Application ibm cloud_pak_for_business_automation 21.0.1 Yes
Application ibm cloud_pak_for_business_automation 21.0.1 Yes
Application ibm cloud_pak_for_business_automation 21.0.1 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.2 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 21.0.3 Yes
Application ibm cloud_pak_for_business_automation 22.0.1 Yes
Application ibm cloud_pak_for_business_automation 22.0.1 Yes
Application ibm cloud_pak_for_business_automation 22.0.1 Yes
Application ibm cloud_pak_for_business_automation 22.0.1 Yes
Application ibm cloud_pak_for_business_automation 22.0.1 Yes
Application ibm cloud_pak_for_business_automation 22.0.1 Yes
Application ibm cloud_pak_for_business_automation 22.0.1 Yes
Application ibm cloud_pak_for_business_automation 22.0.2 Yes
Application ibm cloud_pak_for_business_automation 22.0.2 Yes
Application ibm cloud_pak_for_business_automation 22.0.2 Yes
Application ibm cloud_pak_for_business_automation 22.0.2 Yes
Application ibm cloud_pak_for_business_automation 22.0.2 Yes
Application ibm cloud_pak_for_business_automation 22.0.2 Yes
Application ibm cloud_pak_for_business_automation 22.0.2 Yes
Application ibm cloud_pak_for_business_automation 23.0.1 Yes

References