Local Email Sending Vulnerability in IBM Cloud Orchestrator
CVE-2019-4394
2.3LOW
What is CVE-2019-4394?
IBM Cloud Orchestrator versions 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 may allow local users to leverage specific API functionalities to send unsolicited emails. This could lead to unauthorized dissemination of information and potentially violate privacy policies.
Affected Version(s)
Cloud Orchestrator 2.4
Cloud Orchestrator 2.4.0.1
Cloud Orchestrator 2.4.0.2