Rewterz
Rewterz Threat Alert – CryptBot Trojan – Active IOCs
February 27, 2023
Rewterz
Rewterz Threat Advisory – CVE-2022-40237 – IBM MQ for HPE NonStop Vulnerability
February 28, 2023

Rewterz Threat Advisory – CVE-2023-22860 – IBM Cloud Pak for Business Automation Vulnerability

Severity

Medium

Analysis Summary

CVE-2023-22860

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Impact

  • Cross-Site Scripting

Indicators Of Compromise

CVE

  • CVE-2023-22860

Affected Vendors

IBM

Affected Products

  • IBM Cloud Pak for Business Automation 18.0.0
  • IBM Cloud Pak for Business Automation 18.0.1
  • IBM Cloud Pak for Business Automation 18.0.2
  • IBM Cloud Pak for Business Automation 19.0.1
  • IBM Cloud Pak for Business Automation 19.0.2
  • IBM Cloud Pak for Business Automation 19.0.3
  • IBM Cloud Pak for Business Automation 20.0.1
  • IBM Cloud Pak for Business Automation 20.0.2
  • IBM Cloud Pak for Business Automation 20.0.3
  • IBM Cloud Pak for Business Automation 21.0.1
  • IBM Cloud Pak for Business Automation 21.0.2
  • IBM Cloud Pak for Business Automation 21.0.3
  • IBM Cloud Pak for Business Automation 22.0.1

Remediation

Refer to IBM Security Advisory for patch, upgrade or suggested workaround information.

IBM Security Advisory