IBM Cloud Pak for Automation authentication bypass
Published Feb 29, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.40%
Description
IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration. IBM X-Force ID: 261130.
Affected products
-
- Version 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | Cloud Pak for Automation | unaffected |
|
- 18.0.0
- 18.0.1
- 18.0.2
- 19.0.1
- 19.0.2
- 19.0.3
- 20.0.1
- 20.0.2
- 20.0.3
- 21.0.1
- 21.0.1
- 21.0.1
- 21.0.1
- 21.0.1
- 21.0.1
- 21.0.1
- 21.0.1
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.2
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 21.0.3
- 22.0.1
- 22.0.1
- 22.0.1
- 22.0.1
- 22.0.1
- 22.0.1
- 22.0.1
- 22.0.2
- 22.0.2
- 22.0.2
- 22.0.2
- 22.0.2
- 22.0.2
- 22.0.2
- 23.0.1
-
- Version 18.0.0StatusaffectedConstraints-
- Version 18.0.1StatusaffectedConstraints-
- Version 18.0.2StatusaffectedConstraints-
- Version 19.0.1StatusaffectedConstraints-
- Version 19.0.2StatusaffectedConstraints-
- Version 19.0.3StatusaffectedConstraints-
- Version 20.0.1StatusaffectedConstraints-
- Version 20.0.2StatusaffectedConstraints-
- Version 20.0.3StatusaffectedConstraints-
- Version 21.0.1StatusaffectedConstraints-
- Version 21.0.2StatusaffectedConstraints-
- Version 21.0.3StatusaffectedConstraints-
- Version 22.0.1StatusaffectedConstraints-
- Version 22.0.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | Cloud Pak for Automation | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-42184 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/261130 vdb-entryVendor Advisory
- https://www.ibm.com/support/pages/node/7015271 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-42184 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/261130 | vdb-entryVendor Advisory | |
| https://www.ibm.com/support/pages/node/7015271 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.