CVE-2023-30993: IBM Cloud Pak for Security information disclosure
IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another tenant's account. IBM X-Force ID: 254136.
Other sources
IBM Cloud Pak for Security (CP4S) could allow an attacker with a valid API key for one tenant to access data from another tenant's account.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-30993.
What is the severity of CVE-2023-30993?
The severity of CVE-2023-30993 is high with a CVSS score of 7.5.
What is the affected software in this vulnerability?
The affected software in this vulnerability is IBM Cloud Pak for Security (CP4S) version 1.9.0.0 through 1.9.2.0.
How can an attacker exploit CVE-2023-30993?
An attacker with a valid API key for one tenant can access data from another tenant's account in IBM Cloud Pak for Security (CP4S) versions 1.9.0.0 through 1.9.2.0.
Where can I find more information about CVE-2023-30993?
You can find more information about CVE-2023-30993 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/254136), [Reference 2](https://www.ibm.com/support/pages/node/6995221).