IBM Observability with Instana missing authentication
CVE-2023-27290
9.1CRITICAL
What is CVE-2023-27290?
IBM Instana's Docker-based datastores do not enforce authentication, allowing unauthorized access to sensitive data. Attackers within the network may exploit this flaw to gain read/write access to the datastores, posing a significant risk of data manipulation and exposure. This vulnerability affects multiple versions of IBM Observability with Instana, emphasizing the need for immediate remediation to protect the integrity of stored information.
Affected Version(s)
Observability with Instana 239-0 < 239-2
Observability with Instana 241-0 < 241-2
Observability with Instana 243-0