First published: Fri Nov 18 2016(Updated: )
A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacker after authentication to enumerate valid users of the system. IBM X-Force ID: 109394.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Orchestrator Enterprise | =2.3.0.0 | |
IBM Cloud Orchestrator Enterprise | =2.3.0.1 | |
IBM Cloud Orchestrator Enterprise | =2.4.0.0 | |
IBM Cloud Orchestrator Enterprise | =2.4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0205 is considered to have a medium severity level due to its potential for user enumeration.
To fix CVE-2016-0205, it is recommended to upgrade to IBM Cloud Orchestrator versions 2.4.0.2 or higher.
CVE-2016-0205 affects users of IBM Cloud Orchestrator versions 2.3, 2.3.0.1, 2.4, and 2.4.0.1.
An attacker with authenticated access can enumerate valid users in the system due to CVE-2016-0205.
CVE-2016-0205 was disclosed in March 2016.