First published: Thu Jun 29 2023(Updated: )
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Data | =4.0 | |
<=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-27877 is high.
CVE-2023-27877 allows an attacker to obtain sensitive information from the database connected to IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0.
The vulnerability ID for this security issue in IBM Planning Analytics Cartridge for Cloud Pak for Data is CVE-2023-27877.
An attacker can exploit CVE-2023-27877 by exploiting an insecure password policy to the CouchDB server and collecting sensitive information from the database.
To fix CVE-2023-27877 in IBM Planning Analytics Cartridge for Cloud Pak for Data, update to a version that addresses the insecure password policy.