Ibm · Ibm Watson Machine Learning · CVE-2023-30444
**Name of the Vulnerable Software and Affected Versions**
IBM Watson Machine Learning on Cloud Pak for Data versions 4.0 through 4.5
**Description**
The issue allows an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. This is due to a server-side request forgery (SSRF) vulnerability.
**Recommendations**
For versions 4.0 and 4.5, consider restricting access to sensitive network resources to minimize the risk of exploitation.
As a temporary workaround, consider implementing additional authentication or authorization checks on outgoing requests to prevent unauthorized access.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.