CVE-2015-7494: Low severity IBM Cloud Orchestrator vulnerability
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7494?
CVE-2015-7494 is classified as a medium severity vulnerability.
How do I fix CVE-2015-7494?
To remediate CVE-2015-7494, apply the latest patches and updates provided by IBM for the affected versions.
Who is affected by CVE-2015-7494?
CVE-2015-7494 affects IBM Cloud Orchestrator versions 2.4, 2.5 and certain versions of IBM SmartCloud Orchestrator.
What actions can be exploited in CVE-2015-7494?
CVE-2015-7494 can be exploited through a /services/[action]/launch API call by an authenticated domain admin user.
What kind of resources can be affected by CVE-2015-7494?
CVE-2015-7494 allows an authenticated domain admin user to modify cross-domain resources.