CVE-2023-38372

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM X-Force ID: 261201.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:watson_iot_platform:1.0:*:*:*:*:*:*:*

History

14 Feb 2025, 15:52

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/261201 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/261201 - Vendor Advisory
References () https://www.ibm.com/support/pages/node/7020635 - () https://www.ibm.com/support/pages/node/7020635 - Vendor Advisory
First Time Ibm watson Iot Platform
Ibm
CPE cpe:2.3:a:ibm:watson_iot_platform:1.0:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

21 Nov 2024, 08:13

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/261201 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/261201 -
References () https://www.ibm.com/support/pages/node/7020635 - () https://www.ibm.com/support/pages/node/7020635 -
Summary
  • (es) Un atacante no autorizado que haya obtenido un token de autenticación de seguridad de IBM Watson IoT Platform 1.0 puede utilizarlo para hacerse pasar por un usuario de plataforma autorizado. ID de IBM X-Force: 261201.

29 Feb 2024, 01:40

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:40

Updated : 2025-02-14 15:52


NVD link : CVE-2023-38372

Mitre link : CVE-2023-38372

CVE.ORG link : CVE-2023-38372


JSON object : View

Products Affected

ibm

  • watson_iot_platform
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo