Information Disclosure in IBM Cloud App Management by IBM
CVE-2019-4751

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
24 April 2020

Summary

IBM Cloud App Management versions 2019.3.0 and 2019.4.0 are prone to an information disclosure vulnerability that occurs when certain API requests reveal stack traces. This disclosure can potentially provide attackers with sensitive details regarding the application's implementation, which may assist them in crafting further attacks. For more information, you can refer to the official IBM support documentation and the IBM X-Force database entry.

Affected Version(s)

Cloud App Management 2019.3.0

Cloud App Management 2019.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.