Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fwv-9wqg-4pm8

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.

EPSS

Процентиль: 9%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
6 месяцев назад

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.

EPSS

Процентиль: 9%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639