Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-30444

Опубликовано: 27 апр. 2023
Источник: nvd
CVSS3: 7.1
CVSS3: 6.5
EPSS Низкий

Описание

IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:watson_machine_learning_on_cloud_pak_for_data:4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watson_machine_learning_on_cloud_pak_for_data:4.5:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00064
Низкий

7.1 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.1
github
почти 3 года назад

IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.

EPSS

Процентиль: 20%
0.00064
Низкий

7.1 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-918