First published: Fri Jun 14 2019(Updated: )
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158338.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Private | >=2.1.0<=2.1.0.3 | |
IBM Cloud Private | =3.1.0 | |
IBM Cloud Private | =3.1.1 | |
IBM Cloud Private | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-4142.
CVE-2019-4142 has a severity rating of 8.8, which is considered high.
The affected software for CVE-2019-4142 is IBM Cloud Private versions 2.1.0, 3.1.0, 3.1.1, and 3.1.2.
CVE-2019-4142 is a vulnerability that allows an attacker to execute malicious and unauthorized actions from a trusted user.
To fix CVE-2019-4142, update IBM Cloud Private to a version that is not vulnerable.