2024-05-02 16:03:31 +00:00
{
"id" : "CVE-2023-47727" ,
"sourceIdentifier" : "psirt@us.ibm.com" ,
"published" : "2024-05-02T15:15:06.680" ,
2024-05-02 20:03:31 +00:00
"lastModified" : "2024-05-02T18:00:37.360" ,
"vulnStatus" : "Awaiting Analysis" ,
2024-05-02 16:03:31 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "psirt@us.ibm.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
{
"source" : "psirt@us.ibm.com" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-1287"
}
]
}
] ,
"references" : [
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/272089" ,
"source" : "psirt@us.ibm.com"
} ,
{
"url" : "https://www.ibm.com/support/pages/node/7149968" ,
"source" : "psirt@us.ibm.com"
}
]
}