First published: Fri Mar 03 2023(Updated: )
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Observability with Instana | >=239-0<=239-2 | |
IBM Observability with Instana | >=241-0<=241-2 | |
IBM Observability with Instana | =243-0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-27290 is critical.
An attacker within the network can exploit CVE-2023-27290 by accessing the datastores without authentication and gaining read/write access.
Versions 239-0 through 239-2, 241-0 through 241-2, and 243-0 of IBM Observability with Instana are affected by CVE-2023-27290.
The IBM X-Force ID for CVE-2023-27290 is 248737.
To fix CVE-2023-27290, it is recommended to update to a version of IBM Observability with Instana that requires authentication for the Docker based datastores.