First published: Thu Sep 28 2023(Updated: )
IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Observability with Instana | >=1.0.243<1.0.255 | |
<=1.0 Build version .243-.254 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37404 is a vulnerability in IBM Observability with Instana that could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack.
The severity of CVE-2023-37404 is critical, with a severity value of 9.8.
IBM Observability with Instana versions 1.0.243 through 1.0.254, including build version .243-.254, are affected by CVE-2023-37404.
An attacker can exploit CVE-2023-37404 by performing a successful DNS poisoning attack on the network.
You can find more information about CVE-2023-37404 at the IBM X-Force ID: 259789.