CVE-2023-27877: IBM Cloud Pak For Data

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.

Affected products

  • IBM Cloud Pak For Data: version 4.0 only

Published 2023-07-19. Last modified 2026-06-17.