User Creation Vulnerability in IBM Intelligent Operations Center
CVE-2019-4066
8.8HIGH
Summary
A security vulnerability exists in IBM Intelligent Operations Center (IOC) versions 5.1.0 through 5.2.0, allowing authenticated users to create arbitrary users. This misconfiguration poses serious ID management concerns and may facilitate unauthorized code execution, potentially compromising the integrity of the system. Organizations utilizing affected versions should review their user management protocols and apply updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Intelligent Operations Center 5.1.0
Intelligent Operations Center 5.1.0.1
Intelligent Operations Center 5.1.0.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved