CVE-2023-50940
02.02.2024, 01:15
IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 275130.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | powersc | 1.3 |
ibm | powersc | 2.0 |
ibm | powersc | 2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-942 - Permissive Cross-domain Policy with Untrusted DomainsThe software uses a cross-domain policy file that includes domains that should not be trusted.
- CWE-697 - Incorrect ComparisonThe software compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.