IBM Cloud Pak for Multicloud Management Monitoring privilege escalation
CVE-2022-42438
7.5HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 8 February 2023
What is CVE-2022-42438?
An access control vulnerability in IBM Cloud Pak for Multicloud Management versions 2.0 and 2.3 allows unauthorized users to access administrative functionalities by manipulating URL paths. This flaw may lead to significant security risks as users without appropriate permissions could perform sensitive tasks, potentially compromising the integrity and management of the cloud environment.
Affected Version(s)
Cloud Pak for Multicloud Management Monitoring 2.0, 2.3