CVE-2015-7494
2.8LOW
Summary
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.
Affected Version(s)
Cloud Orchestrator 2.2
Cloud Orchestrator 2.2.0.1
Cloud Orchestrator 2.3
References
CVSS V3.1
Score:
2.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved