First published: Thu Oct 24 2019(Updated: )
IBM Cloud Orchestrator stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Orchestrator Enterprise | >=2.4<=2.4.0.5 | |
IBM Cloud Orchestrator Enterprise | >=2.5<=2.5.0.9 | |
IBM Cloud Orchestrator Enterprise | >=2.4<=2.4.0.5 | |
IBM Cloud Orchestrator Enterprise | >=2.5<=2.5.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4397 is rated as moderate due to its potential for information disclosure.
To fix CVE-2019-4397, it is recommended to upgrade to a version of IBM Cloud Orchestrator that does not expose sensitive information in URL parameters.
CVE-2019-4397 affects IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise versions 2.5 through 2.5.0.9 and versions between 2.4.0.5 and 2.4.
CVE-2019-4397 may lead to sensitive information disclosure if unauthorized parties access URLs through logs or browser history.
Yes, CVE-2019-4397 is an application level vulnerability specifically related to the IBM Cloud Orchestrator.