Sensitive Data Exposure in IBM Cloud Orchestrator
CVE-2019-4397
5.3MEDIUM
Summary
IBM Cloud Orchestrator and its Enterprise version 2.5 up to 2.5.0.9 and 2.4 up to 2.4.0.5 are vulnerable due to the improper handling of sensitive information stored in URL parameters. This weakness allows unauthorized parties to potentially access confidential data through server logs, referrer headers, or browser history, leading to possible exploitation and information leakage.
Affected Version(s)
Cloud Orchestrator 2.4
Cloud Orchestrator 2.4.0.1
Cloud Orchestrator 2.4.0.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved