IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a privileged user to inject inject malicious data using a specially crafted HTTP request due to improper input validation.
| Software | From | Fixed in |
|---|---|---|
| ibm / cloud_pak_for_security | 1.4.0.0 | 1.4.0.0.x |
| ibm / cloud_pak_for_security | 1.5.0.0 | 1.5.0.0.x |
| ibm / cloud_pak_for_security | 1.5.0.1 | 1.5.0.1.x |
| ibm / cloud_pak_for_security | 1.6.0.0 | 1.6.0.0.x |
| ibm / cloud_pak_for_security | 1.6.0.1 | 1.6.0.1.x |