Sensitive Data Exposure in IBM Cloud Orchestrator
CVE-2019-4397
5.3MEDIUM
What is CVE-2019-4397?
IBM Cloud Orchestrator and its Enterprise version 2.5 up to 2.5.0.9 and 2.4 up to 2.4.0.5 are vulnerable due to the improper handling of sensitive information stored in URL parameters. This weakness allows unauthorized parties to potentially access confidential data through server logs, referrer headers, or browser history, leading to possible exploitation and information leakage.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cloud Orchestrator 2.4
Cloud Orchestrator 2.4.0.1
Cloud Orchestrator 2.4.0.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved