First published: Tue Mar 21 2023(Updated: )
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an attacker to obtain sensitive information. IBM X-Force ID: 248740.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Watson CloudPak for Data Data Stores | <=4.6.0,4.6.1, 4.6.2, 4.6.3 | |
IBM Watson CP4D Data Stores | =4.6.0 | |
IBM Watson CP4D Data Stores | =4.6.1 | |
IBM Watson CP4D Data Stores | =4.6.2 | |
IBM Watson CP4D Data Stores | =4.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27291 is considered a high severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2023-27291, upgrade to a version of IBM Watson CP4D Data Stores that implements encryption for sensitive and critical information.
Versions 4.6.0, 4.6.1, 4.6.2, and 4.6.3 of IBM Watson CP4D Data Stores are vulnerable as per CVE-2023-27291.
CVE-2023-27291 puts sensitive and critical information at risk as it is not encrypted before storage or transmission.
Currently, there is no documented workaround for CVE-2023-27291, and upgrading to a secure version is recommended.