CVE-2023-50959: IBM Cloud Pak for Business Automation information disclosure
IBM Business Automation Workflow may allow end users to query more documents than expected from a connected Enterprise Content Management system when configured to use a system account.
Other sources
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expected from a connected Enterprise Content Management system when configured to use a system account. IBM X-Force ID: 275938.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50959?
CVE-2023-50959 has a not specified severity rating that indicates potential risks related to document queries in IBM Business Automation Workflow.
How do I fix CVE-2023-50959?
To fix CVE-2023-50959, apply the latest patches or updates provided by IBM for the affected versions of Cloud Pak for Business Automation.
Which versions are affected by CVE-2023-50959?
CVE-2023-50959 affects IBM Cloud Pak for Business Automation versions 18.0.0 through 23.0.2.
What type of issue does CVE-2023-50959 represent?
CVE-2023-50959 represents a vulnerability that allows unintended document access from an Enterprise Content Management system.
Who is affected by CVE-2023-50959?
End users of IBM Business Automation Workflow who utilize a system account for interacting with connected Enterprise Content Management systems are affected by CVE-2023-50959.