IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6450849 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/198919 | vdb entry vendor advisory |