CVE-2023-27291: IBM Watson CP4D Data Stores information disclosure
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an attacker to obtain sensitive information. IBM X-Force ID: 248740.
Other sources
IBM Watson CP4D Data Stores does not encrypt sensitive or critical information before storage or transmission which could allow an attacker to obtain sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27291?
CVE-2023-27291 is considered a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2023-27291?
To fix CVE-2023-27291, upgrade to a version of IBM Watson CP4D Data Stores that implements encryption for sensitive and critical information.
Which versions of IBM Watson CP4D Data Stores are affected by CVE-2023-27291?
Versions 4.6.0, 4.6.1, 4.6.2, and 4.6.3 of IBM Watson CP4D Data Stores are vulnerable as per CVE-2023-27291.
What types of data are at risk due to CVE-2023-27291?
CVE-2023-27291 puts sensitive and critical information at risk as it is not encrypted before storage or transmission.
Is there a workaround for CVE-2023-27291 before applying the fix?
Currently, there is no documented workaround for CVE-2023-27291, and upgrading to a secure version is recommended.