CVE-2023-47716Incorrect Authorization in IBM Filenet Content Manager

Severity
8.8HIGHNVD
CNA6.3
EPSS
0.0%
top 93.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1

Description

IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. IBM X-Force ID: 271656.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDibm/cp4ba_filenet_content_manager21.0.3, 23.0.1+1
CVEListV5ibm/filenet_content_manager5.5.8.0, 5.5.10.0, 5.5.11.0
NVDibm/filenet_content_manager5.5.10, 5.5.11, 5.5.8+2

🔴Vulnerability Details

2
GHSA
GHSA-9whp-qh87-g9m8: IBM CP4BA - Filenet Content Manager Component 52024-03-01
CVEList
IBM FileNet Content Manager privilege escalation2024-03-01
CVE-2023-47716 — Incorrect Authorization in IBM | cvebase