First published: Fri Jun 14 2019(Updated: )
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Private | >=1.0.0<=3.0.1 | |
IBM Cloud Private | >=2.1.0<=2.3.1 | |
Redhat Openshift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4239 is 5.5, which is considered medium.
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) and IBM Cloud Private (1.0.0 through 3.0.1) are affected.
CVE-2019-4239 allows a local user to read user credentials in plain text.
Yes, versions 2.1.0 through 2.3.1 of IBM Cloud Private are also affected by CVE-2019-4239.
You can find more information about CVE-2019-4239 on the IBM X-Force ID: 159465 and the IBM support website.