CVE Vulnerabilities

CVE-2022-42438

Direct Request ('Forced Browsing')

Published: Feb 08, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
Cloud_pak_for_multicloud_management_monitoringIbm2.0.0 (including)2.3.0 (excluding)
Cloud_pak_for_multicloud_management_monitoringIbm2.3.0 (including)2.3.0 (including)
Cloud_pak_for_multicloud_management_monitoringIbm2.3.0-fixpack2 (including)2.3.0-fixpack2 (including)
Cloud_pak_for_multicloud_management_monitoringIbm2.3.0-fixpack3 (including)2.3.0-fixpack3 (including)
Cloud_pak_for_multicloud_management_monitoringIbm2.3.0-fixpack4 (including)2.3.0-fixpack4 (including)
Cloud_pak_for_multicloud_management_monitoringIbm2.3.0-fixpack5 (including)2.3.0-fixpack5 (including)

Potential Mitigations

References