Vulnerability Details CVE-2023-38367
                IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration.  IBM X-Force ID:  261130.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.001
                        
                    
                    
                        
                            EPSS Ranking 19.0%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 6.5
                        
                    
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2023-38367
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:18.0.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:18.0.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:18.0.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:19.0.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:19.0.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:19.0.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:20.0.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:20.0.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:20.0.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:21.0.3
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:22.0.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:22.0.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:cloud_pak_for_business_automation:23.0.1