5.5

CVE-2016-0203

A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects where the user belongs to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Orchestrator Version 2.4
Ibm ≫ Cloud Orchestrator Version 2.4.0.1
Ibm ≫ Cloud Orchestrator Version 2.4.0.2
Ibm ≫ Cloud Orchestrator Version 2.4.0.3
Ibm ≫ Cloud Orchestrator Version 2.5
Ibm ≫ Cloud Orchestrator Version 2.5.01
Ibm ≫ Smartcloud Orchestrator Version 2.3
Ibm ≫ Smartcloud Orchestrator Version 2.3.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.268
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.ibm.com/support/docview.wss?uid=swg2C1000140
Patch
Vendor Advisory
http://www.securityfocus.com/bid/94440
Third Party Advisory
VDB Entry