7.5

CVE-2024-22341

IBM Watson Query on Cloud Pak for Data information disclosure

IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privilege management.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmWatson Query With Cloud Pak For Data Version >= 4.0 <= 4.0.9
IbmWatson Query With Cloud Pak For Data Version >= 4.5 <= 4.5.3
IbmWatson Query With Cloud Pak For Data Version >= 4.6 <= 4.6.6
IbmWatson Query With Cloud Pak For Data Version >= 4.7 <= 4.7.4
IbmWatson Query With Cloud Pak For Data Version >= 4.8 <= 4.8.7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
psirt@us.ibm.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-73 External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.