First published: Mon Nov 19 2018(Updated: )
IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150901.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Private | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1841 is medium (5.5).
A local user can obtain the CA Private Key in IBM Cloud Private 2.1.0 due to it being world readable in the boot/master node.
The IBM X-Force ID associated with CVE-2018-1841 is 150901.
The Common Weakness Enumeration (CWE) ID for CVE-2018-1841 is 200.
You can find more information about CVE-2018-1841 [here](https://www.ibm.com/support/docview.wss?uid=ibm10739851).