Information Disclosure Vulnerability in IBM Cloud Private
CVE-2019-4116
5.5MEDIUM
Summary
The vulnerability in IBM Cloud Private allows sensitive information to be exposed through installer logs. This exposure could enable attackers to gain insights into the system's configuration and potentially exploit other vulnerabilities. It is crucial for users to take preventive measures to secure their installations, as the leaked information poses a risk of further attacks. Organizations should audit their logs and enhance their security posture to mitigate the risks associated with this vulnerability.
Affected Version(s)
Cloud Private 2.1.0
Cloud Private 3.1.0
Cloud Private 3.1.1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved