Lucene search

K
nvd[email protected]NVD:CVE-2023-40691
HistoryDec 18, 2023 - 9:15 p.m.

CVE-2023-40691

2023-12-1821:15:08
CWE-200
web.nvd.nist.gov
1
ibm cloud pak
business automation
sensitive information
configuration
developer
administrator
ibm x-force

4.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

0.0005 Low

EPSS

Percentile

19.1%

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 may reveal sensitive information contained in application configuration to developer and administrator users. IBM X-Force ID: 264805.

Affected configurations

NVD
Node
ibmcloud_pak_for_business_automationMatch18.0.0
OR
ibmcloud_pak_for_business_automationMatch18.0.2
OR
ibmcloud_pak_for_business_automationMatch19.0.1
OR
ibmcloud_pak_for_business_automationMatch19.0.3
OR
ibmcloud_pak_for_business_automationMatch20.0.1
OR
ibmcloud_pak_for_business_automationMatch20.0.3
OR
ibmcloud_pak_for_business_automationMatch21.0.1-
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_005
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_006
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_007
OR
ibmcloud_pak_for_business_automationMatch21.0.1interim_fix_008
OR
ibmcloud_pak_for_business_automationMatch21.0.3-
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_005
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_006
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_007
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_008
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_009
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_010
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_011
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_012
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_013
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_014
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_015
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_016
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_017
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_018
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_019
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_020
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_021
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_022
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_023
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_024
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_025
OR
ibmcloud_pak_for_business_automationMatch21.0.3interim_fix_026
OR
ibmcloud_pak_for_business_automationMatch22.0.2-
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_004
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_005
OR
ibmcloud_pak_for_business_automationMatch22.0.2interim_fix_006
OR
ibmcloud_pak_for_business_automationMatch23.0.1-
OR
ibmcloud_pak_for_business_automationMatch23.0.1interim_fix_001
OR
ibmcloud_pak_for_business_automationMatch23.0.1interim_fix_002
OR
ibmcloud_pak_for_business_automationMatch23.0.1interim_fix_003
OR
ibmcloud_pak_for_business_automationMatch23.0.1interim_fix_004

4.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

0.0005 Low

EPSS

Percentile

19.1%

Related for NVD:CVE-2023-40691