CVE-2023-23469: IBM Cloud Pak for Business Automation information disclosure
IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 244504.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-23469.
What is the severity level of CVE-2023-23469?
The severity level of CVE-2023-23469 is medium (3.3).
How does CVE-2023-23469 impact IBM ICP4A - Automation Decision Services?
CVE-2023-23469 allows web pages to be stored locally, which can be read by another user on the system, impacting the security of IBM ICP4A - Automation Decision Services.
Which versions of IBM Cloud Pak for Business Automation are affected by CVE-2023-23469?
IBM Cloud Pak for Business Automation versions 18.0.0 to 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.2 are affected by CVE-2023-23469.
How can I fix the vulnerability CVE-2023-23469?
To fix the vulnerability CVE-2023-23469, it is recommended to install the appropriate security updates or interim fixes provided by IBM Cloud Pak for Business Automation.