CVE Vulnerabilities

CVE-2023-38367

Published: Feb 29, 2024 | Modified: Mar 27, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration. IBM X-Force ID: 261130.

Affected Software

NameVendorStart VersionEnd Version
Cloud_pak_for_business_automationIbm18.0.0 (including)18.0.0 (including)
Cloud_pak_for_business_automationIbm18.0.1 (including)18.0.1 (including)
Cloud_pak_for_business_automationIbm18.0.2 (including)18.0.2 (including)
Cloud_pak_for_business_automationIbm19.0.1 (including)19.0.1 (including)
Cloud_pak_for_business_automationIbm19.0.2 (including)19.0.2 (including)
Cloud_pak_for_business_automationIbm19.0.3 (including)19.0.3 (including)
Cloud_pak_for_business_automationIbm20.0.1 (including)20.0.1 (including)
Cloud_pak_for_business_automationIbm20.0.2 (including)20.0.2 (including)
Cloud_pak_for_business_automationIbm20.0.3 (including)20.0.3 (including)
Cloud_pak_for_business_automationIbm21.0.1 (including)21.0.1 (including)
Cloud_pak_for_business_automationIbm21.0.1-interim_fix_001 (including)21.0.1-interim_fix_001 (including)
Cloud_pak_for_business_automationIbm21.0.1-interim_fix_002 (including)21.0.1-interim_fix_002 (including)
Cloud_pak_for_business_automationIbm21.0.1-interim_fix_003 (including)21.0.1-interim_fix_003 (including)
Cloud_pak_for_business_automationIbm21.0.1-interim_fix_004 (including)21.0.1-interim_fix_004 (including)
Cloud_pak_for_business_automationIbm21.0.1-interim_fix_005 (including)21.0.1-interim_fix_005 (including)
Cloud_pak_for_business_automationIbm21.0.1-interim_fix_006 (including)21.0.1-interim_fix_006 (including)
Cloud_pak_for_business_automationIbm21.0.1-interim_fix_007 (including)21.0.1-interim_fix_007 (including)
Cloud_pak_for_business_automationIbm21.0.2 (including)21.0.2 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_001 (including)21.0.2-interim_fix_001 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_0012 (including)21.0.2-interim_fix_0012 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_002 (including)21.0.2-interim_fix_002 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_003 (including)21.0.2-interim_fix_003 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_004 (including)21.0.2-interim_fix_004 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_005 (including)21.0.2-interim_fix_005 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_006 (including)21.0.2-interim_fix_006 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_007 (including)21.0.2-interim_fix_007 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_008 (including)21.0.2-interim_fix_008 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_009 (including)21.0.2-interim_fix_009 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_010 (including)21.0.2-interim_fix_010 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_011 (including)21.0.2-interim_fix_011 (including)
Cloud_pak_for_business_automationIbm21.0.2-interim_fix_012 (including)21.0.2-interim_fix_012 (including)
Cloud_pak_for_business_automationIbm21.0.3 (including)21.0.3 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_001 (including)21.0.3-interim_fix_001 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_002 (including)21.0.3-interim_fix_002 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_003 (including)21.0.3-interim_fix_003 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_004 (including)21.0.3-interim_fix_004 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_005 (including)21.0.3-interim_fix_005 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_006 (including)21.0.3-interim_fix_006 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_007 (including)21.0.3-interim_fix_007 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_008 (including)21.0.3-interim_fix_008 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_009 (including)21.0.3-interim_fix_009 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_010 (including)21.0.3-interim_fix_010 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_011 (including)21.0.3-interim_fix_011 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_012 (including)21.0.3-interim_fix_012 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_013 (including)21.0.3-interim_fix_013 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_014 (including)21.0.3-interim_fix_014 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_015 (including)21.0.3-interim_fix_015 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_016 (including)21.0.3-interim_fix_016 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_017 (including)21.0.3-interim_fix_017 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_018 (including)21.0.3-interim_fix_018 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_019 (including)21.0.3-interim_fix_019 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_020 (including)21.0.3-interim_fix_020 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_021 (including)21.0.3-interim_fix_021 (including)
Cloud_pak_for_business_automationIbm21.0.3-interim_fix_022 (including)21.0.3-interim_fix_022 (including)
Cloud_pak_for_business_automationIbm22.0.1 (including)22.0.1 (including)
Cloud_pak_for_business_automationIbm22.0.1-interim_fix_001 (including)22.0.1-interim_fix_001 (including)
Cloud_pak_for_business_automationIbm22.0.1-interim_fix_002 (including)22.0.1-interim_fix_002 (including)
Cloud_pak_for_business_automationIbm22.0.1-interim_fix_003 (including)22.0.1-interim_fix_003 (including)
Cloud_pak_for_business_automationIbm22.0.1-interim_fix_004 (including)22.0.1-interim_fix_004 (including)
Cloud_pak_for_business_automationIbm22.0.1-interim_fix_005 (including)22.0.1-interim_fix_005 (including)
Cloud_pak_for_business_automationIbm22.0.1-interim_fix_006 (including)22.0.1-interim_fix_006 (including)
Cloud_pak_for_business_automationIbm22.0.2 (including)22.0.2 (including)
Cloud_pak_for_business_automationIbm22.0.2-interim_fix_001 (including)22.0.2-interim_fix_001 (including)
Cloud_pak_for_business_automationIbm22.0.2-interim_fix_002 (including)22.0.2-interim_fix_002 (including)
Cloud_pak_for_business_automationIbm22.0.2-interim_fix_003 (including)22.0.2-interim_fix_003 (including)
Cloud_pak_for_business_automationIbm22.0.2-interim_fix_004 (including)22.0.2-interim_fix_004 (including)
Cloud_pak_for_business_automationIbm22.0.2-interim_fix_005 (including)22.0.2-interim_fix_005 (including)
Cloud_pak_for_business_automationIbm22.0.2-interim_fix_006 (including)22.0.2-interim_fix_006 (including)
Cloud_pak_for_business_automationIbm23.0.1 (including)23.0.1 (including)

References