CVE-2023-27877: IBM Planning Analytics Cartridge for Cloud Pak for Data information disclosure
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
Other sources
IBM Planning Analytics on Cloud Pak for Data could allow an attacker to obtain sensitive information, due to insecure network policy configuration.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27877?
The severity of CVE-2023-27877 is high.
How does CVE-2023-27877 affect IBM Planning Analytics Cartridge for Cloud Pak for Data?
CVE-2023-27877 allows an attacker to obtain sensitive information from the database connected to IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0.
What is the vulnerability ID for this security issue in IBM Planning Analytics Cartridge for Cloud Pak for Data?
The vulnerability ID for this security issue in IBM Planning Analytics Cartridge for Cloud Pak for Data is CVE-2023-27877.
How can an attacker exploit CVE-2023-27877?
An attacker can exploit CVE-2023-27877 by exploiting an insecure password policy to the CouchDB server and collecting sensitive information from the database.
How can I fix CVE-2023-27877 in IBM Planning Analytics Cartridge for Cloud Pak for Data?
To fix CVE-2023-27877 in IBM Planning Analytics Cartridge for Cloud Pak for Data, update to a version that addresses the insecure password policy.