Sensitive Data Exposure in IBM Cloud Orchestrator
CVE-2019-4397
5.3MEDIUM
What is CVE-2019-4397?
IBM Cloud Orchestrator and its Enterprise version 2.5 up to 2.5.0.9 and 2.4 up to 2.4.0.5 are vulnerable due to the improper handling of sensitive information stored in URL parameters. This weakness allows unauthorized parties to potentially access confidential data through server logs, referrer headers, or browser history, leading to possible exploitation and information leakage.
Affected Version(s)
Cloud Orchestrator 2.4
Cloud Orchestrator 2.4.0.1
Cloud Orchestrator 2.4.0.2