CVE-2023-40694: IBM Watson CP4D Data Stores information disclosure
Published May 6, 2024
·Updated
IBM Watson CP4D Data Store stores potentially sensitive information in log files that could be read by a local user.
Other sources
IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838.
— MITRE
Affected Software
3 affected components
IBM Watson CP4D Data Stores<=4.0.0 - 4.8.4
All of the following
IBM Watson CP4D Data Stores>=4.0.0<4.8.5
redhat Openshift
Event History
May 6, 2024
CVE Published
via IBM·12:00 AM
May 7, 2024
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-40694?
CVE-2023-40694 has been classified with a moderate severity level due to the potential exposure of sensitive information.
2
How do I fix CVE-2023-40694?
To fix CVE-2023-40694, update IBM Watson CP4D Data Stores to a version higher than 4.8.4.
3
What are the affected versions for CVE-2023-40694?
CVE-2023-40694 affects IBM Watson CP4D Data Stores versions 4.0.0 through 4.8.4.
4
What kind of information is exposed in CVE-2023-40694?
CVE-2023-40694 exposes potentially sensitive information stored in log files.
5
Who can exploit CVE-2023-40694?
CVE-2023-40694 can be exploited by a local user who has access to the log files.