Sensitive Data Exposure in IBM Cloud Orchestrator
CVE-2019-4397

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
24 October 2019

Summary

IBM Cloud Orchestrator and its Enterprise version 2.5 up to 2.5.0.9 and 2.4 up to 2.4.0.5 are vulnerable due to the improper handling of sensitive information stored in URL parameters. This weakness allows unauthorized parties to potentially access confidential data through server logs, referrer headers, or browser history, leading to possible exploitation and information leakage.

Affected Version(s)

Cloud Orchestrator 2.4

Cloud Orchestrator 2.4.0.1

Cloud Orchestrator 2.4.0.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.