IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 288178.
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cloud_pak_for_business_automation | Ibm | 18.0.0 (including) | 18.0.2 (including) |
Cloud_pak_for_business_automation | Ibm | 19.0.1 (including) | 19.0.3 (including) |
Cloud_pak_for_business_automation | Ibm | 20.0.1 (including) | 20.0.3 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1 (including) | 21.0.1 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1-interim_fix_001 (including) | 21.0.1-interim_fix_001 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1-interim_fix_002 (including) | 21.0.1-interim_fix_002 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1-interim_fix_003 (including) | 21.0.1-interim_fix_003 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1-interim_fix_004 (including) | 21.0.1-interim_fix_004 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1-interim_fix_005 (including) | 21.0.1-interim_fix_005 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1-interim_fix_006 (including) | 21.0.1-interim_fix_006 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1-interim_fix_007 (including) | 21.0.1-interim_fix_007 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.1-interim_fix_008 (including) | 21.0.1-interim_fix_008 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3 (including) | 21.0.3 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_001 (including) | 21.0.3-interim_fix_001 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_002 (including) | 21.0.3-interim_fix_002 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_003 (including) | 21.0.3-interim_fix_003 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_004 (including) | 21.0.3-interim_fix_004 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_005 (including) | 21.0.3-interim_fix_005 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_006 (including) | 21.0.3-interim_fix_006 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_007 (including) | 21.0.3-interim_fix_007 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_008 (including) | 21.0.3-interim_fix_008 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_009 (including) | 21.0.3-interim_fix_009 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_010 (including) | 21.0.3-interim_fix_010 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_011 (including) | 21.0.3-interim_fix_011 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_012 (including) | 21.0.3-interim_fix_012 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_013 (including) | 21.0.3-interim_fix_013 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_014 (including) | 21.0.3-interim_fix_014 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_015 (including) | 21.0.3-interim_fix_015 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_016 (including) | 21.0.3-interim_fix_016 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_017 (including) | 21.0.3-interim_fix_017 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_018 (including) | 21.0.3-interim_fix_018 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_019 (including) | 21.0.3-interim_fix_019 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_020 (including) | 21.0.3-interim_fix_020 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_021 (including) | 21.0.3-interim_fix_021 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_022 (including) | 21.0.3-interim_fix_022 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_023 (including) | 21.0.3-interim_fix_023 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_024 (including) | 21.0.3-interim_fix_024 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_025 (including) | 21.0.3-interim_fix_025 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_026 (including) | 21.0.3-interim_fix_026 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_028 (including) | 21.0.3-interim_fix_028 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_029 (including) | 21.0.3-interim_fix_029 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_030 (including) | 21.0.3-interim_fix_030 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_031 (including) | 21.0.3-interim_fix_031 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_032 (including) | 21.0.3-interim_fix_032 (including) |
Cloud_pak_for_business_automation | Ibm | 21.0.3-interim_fix_033 (including) | 21.0.3-interim_fix_033 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.1 (including) | 22.0.1 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.1-interim_fix_001 (including) | 22.0.1-interim_fix_001 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.1-interim_fix_002 (including) | 22.0.1-interim_fix_002 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.1-interim_fix_003 (including) | 22.0.1-interim_fix_003 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.1-interim_fix_004 (including) | 22.0.1-interim_fix_004 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.1-interim_fix_005 (including) | 22.0.1-interim_fix_005 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.1-interim_fix_006 (including) | 22.0.1-interim_fix_006 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.2 (including) | 22.0.2 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.2-interim_fix_001 (including) | 22.0.2-interim_fix_001 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.2-interim_fix_002 (including) | 22.0.2-interim_fix_002 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.2-interim_fix_003 (including) | 22.0.2-interim_fix_003 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.2-interim_fix_004 (including) | 22.0.2-interim_fix_004 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.2-interim_fix_005 (including) | 22.0.2-interim_fix_005 (including) |
Cloud_pak_for_business_automation | Ibm | 22.0.2-interim_fix_006 (including) | 22.0.2-interim_fix_006 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.1 (including) | 23.0.1 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.1-interim_fix_001 (including) | 23.0.1-interim_fix_001 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.1-interim_fix_002 (including) | 23.0.1-interim_fix_002 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.1-interim_fix_003 (including) | 23.0.1-interim_fix_003 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.1-interim_fix_004 (including) | 23.0.1-interim_fix_004 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.2 (including) | 23.0.2 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.2-interim_fix_001 (including) | 23.0.2-interim_fix_001 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.2-interim_fix_002 (including) | 23.0.2-interim_fix_002 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.2-interim_fix_003 (including) | 23.0.2-interim_fix_003 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.2-interim_fix_004 (including) | 23.0.2-interim_fix_004 (including) |
Cloud_pak_for_business_automation | Ibm | 23.0.2-interim_fix_005 (including) | 23.0.2-interim_fix_005 (including) |