CVE Vulnerabilities

CVE-2023-50940

Incorrect Comparison

Published: Feb 02, 2024 | Modified: Feb 02, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 275130.

Weakness

The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Powersc Ibm 1.3 (including) 1.3 (including)
Powersc Ibm 2.0 (including) 2.0 (including)
Powersc Ibm 2.1 (including) 2.1 (including)

Extended Description

This Pillar covers several possibilities:

References