First published: Tue May 16 2023(Updated: )
IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another tenant's account. IBM X-Force ID: 254136.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | >=1.9.0.0<=1.9.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.9.0.0 - 1.9.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-30993.
The severity of CVE-2023-30993 is high with a CVSS score of 7.5.
The affected software in this vulnerability is IBM Cloud Pak for Security (CP4S) version 1.9.0.0 through 1.9.2.0.
An attacker with a valid API key for one tenant can access data from another tenant's account in IBM Cloud Pak for Security (CP4S) versions 1.9.0.0 through 1.9.2.0.
You can find more information about CVE-2023-30993 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/254136), [Reference 2](https://www.ibm.com/support/pages/node/6995221).