First published: Fri Oct 25 2019(Updated: )
IBM Cloud Orchestrator uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Orchestrator Enterprise | >=2.4.0.0<=2.4.0.5 | |
IBM Cloud Orchestrator Enterprise | >=2.4.0.0<=2.4.0.5 | |
IBM Cloud Orchestrator Enterprise | >=2.5.0.0<=2.5.0.9 | |
IBM Cloud Orchestrator Enterprise | >=2.5.0.0<=2.5.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4399 has a high severity due to its potential to allow attackers to decrypt sensitive information.
To mitigate CVE-2019-4399, upgrade IBM Cloud Orchestrator to a version that uses stronger cryptographic algorithms.
CVE-2019-4399 affects IBM Cloud Orchestrator versions 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9.
CVE-2019-4399 allows attackers to exploit weaker than expected cryptographic algorithms used in IBM Cloud Orchestrator.
As of now, there is no public indication that CVE-2019-4399 is actively being exploited in the wild.