PT-2023-18977 · Ibm · Ibm Icp4A - Automation Decision Services

Published

2023-02-01

·

Updated

2025-03-26

·

CVE-2023-23469

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM ICP4A - Automation Decision Services versions 18.0.0 through 22.0.2
Description The issue allows web pages to be stored locally, which can then be read by another user on the system.
Recommendations For versions 18.0.0 through 22.0.2, consider implementing access controls to restrict which users can read locally stored web pages, or apply configuration changes to prevent web pages from being stored locally. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-23469

Affected Products

Ibm Icp4A - Automation Decision Services