Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3q6-3rrv-r75p

Опубликовано: 05 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2

allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2

allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.

EPSS

Процентиль: 26%
0.00092
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 года назад

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.

EPSS

Процентиль: 26%
0.00092
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-266