PT-2024-14029 · Ibm · Ibm Cloud Pak For Business Automation

Published

2024-03-31

·

Updated

2024-04-02

·

CVE-2023-50959

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak for Business Automation versions 18.0.0 through 23.0.2
Description The issue allows end users to query more documents than expected from a connected Enterprise Content Management system when configured to use a system account.
Recommendations For versions 18.0.0 through 23.0.2, consider restricting access to the system account to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-50959

Affected Products

Ibm Cloud Pak For Business Automation