First published: Wed Feb 08 2017(Updated: )
A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Orchestrator Enterprise | =2.3 | |
IBM Cloud Orchestrator Enterprise | =2.3.0.1 | |
IBM Cloud Orchestrator Enterprise | =2.4 | |
IBM Cloud Orchestrator Enterprise | =2.4.0.1 | |
IBM Cloud Orchestrator Enterprise | =2.4.0.2 | |
IBM Cloud Orchestrator Enterprise | =2.4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0202 has been classified as a medium severity vulnerability.
To mitigate CVE-2016-0202, it is recommended to upgrade to the latest version of IBM Cloud Orchestrator.
CVE-2016-0202 affects authenticated users of IBM Cloud Orchestrator in versions 2.3, 2.4, and their respective updates.
CVE-2016-0202 allows authenticated users to view tasks from other users within the same domain.
CVE-2016-0202 is a local vulnerability that requires authentication to exploit.