PT-2024-12715 · Ibm · Ibm Cloud Pak Foundational Services Identity Provider

Published

2024-02-29

·

Updated

2024-12-16

·

CVE-2023-38367

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak Foundational Services Identity Provider (idP) API versions 18.0.0 through 22.0.2
Description The issue allows an unauthenticated attacker to perform CRUD operations using an invalid token, potentially enabling them to view, update, delete, or create an IdP configuration.
Recommendations For versions 18.0.0 through 22.0.2, consider disabling the API endpoint that allows CRUD operations with an invalid token until a patch is available. Restrict access to the IdP configuration to minimize the risk of exploitation. Avoid using the idP API with invalid tokens in the affected IBM Cloud Pak for Automation versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-38367

Affected Products

Ibm Cloud Pak Foundational Services Identity Provider