IBM Observability with Instana missing authentication
CVE-2023-27290

9.1CRITICAL

Key Information:

Vendor
IBM
Vendor
CVE Published:
3 March 2023

Summary

IBM Instana's Docker-based datastores do not enforce authentication, allowing unauthorized access to sensitive data. Attackers within the network may exploit this flaw to gain read/write access to the datastores, posing a significant risk of data manipulation and exposure. This vulnerability affects multiple versions of IBM Observability with Instana, emphasizing the need for immediate remediation to protect the integrity of stored information.

Affected Version(s)

Observability with Instana 239-0 < 239-2

Observability with Instana 241-0 < 241-2

Observability with Instana 243-0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.