CVE-2016-0202: Infoleak
Published Feb 8, 2017
·Updated
A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.
Affected Software
6 affected components
IBM Cloud Orchestrator=2.3
IBM Cloud Orchestrator=2.3.0.1
IBM Cloud Orchestrator=2.4
IBM Cloud Orchestrator=2.4.0.1
IBM Cloud Orchestrator=2.4.0.2
IBM Cloud Orchestrator=2.4.0.3
Remediation
Patch Available
Event History
Feb 8, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-0202?
CVE-2016-0202 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2016-0202?
To mitigate CVE-2016-0202, it is recommended to upgrade to the latest version of IBM Cloud Orchestrator.
3
Who is affected by CVE-2016-0202?
CVE-2016-0202 affects authenticated users of IBM Cloud Orchestrator in versions 2.3, 2.4, and their respective updates.
4
What type of attack does CVE-2016-0202 enable?
CVE-2016-0202 allows authenticated users to view tasks from other users within the same domain.
5
Is CVE-2016-0202 a remote or local vulnerability?
CVE-2016-0202 is a local vulnerability that requires authentication to exploit.