First published: Mon Aug 05 2019(Updated: )
IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to the system as another user. IBM X-Force ID: 160512.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Private | >=2.1.0<=2.1.0.3 | |
IBM Cloud Private | =3.1.0 | |
IBM Cloud Private | =3.1.1 | |
IBM Cloud Private | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4284 is a vulnerability in IBM Cloud Private that allows a local privileged user to obtain sensitive OIDC tokens from log files.
A local privileged user can exploit CVE-2019-4284 by accessing the log files and extracting sensitive OIDC tokens.
The severity of CVE-2019-4284 is medium with a CVSS score of 4.4.
IBM Cloud Private versions 2.1.0, 3.1.0, 3.1.1, and 3.1.2 are affected by CVE-2019-4284.
To fix CVE-2019-4284, IBM recommends updating to the latest version of IBM Cloud Private.