IBM Observability with Instana missing authentication
CVE-2023-27290
9.1CRITICAL
Summary
IBM Instana's Docker-based datastores do not enforce authentication, allowing unauthorized access to sensitive data. Attackers within the network may exploit this flaw to gain read/write access to the datastores, posing a significant risk of data manipulation and exposure. This vulnerability affects multiple versions of IBM Observability with Instana, emphasizing the need for immediate remediation to protect the integrity of stored information.
Affected Version(s)
Observability with Instana 239-0 < 239-2
Observability with Instana 241-0 < 241-2
Observability with Instana 243-0
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved