CVE-2015-7494

2.8LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
8 February 2017

Summary

A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.

Affected Version(s)

Cloud Orchestrator 2.2

Cloud Orchestrator 2.2.0.1

Cloud Orchestrator 2.3

References

CVSS V3.1

Score:
2.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.