Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.3
CVE-2026-14893
- EPSS 0.33%
- Veröffentlicht 28.07.2026 20:36:57
- Zuletzt bearbeitet 30.07.2026 14:08:40
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
9.8
CVE-2023-37404
- EPSS 0.78%
- Veröffentlicht 04.10.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:39
IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789.
9.1
CVE-2023-27290
- EPSS 8.57%
- Veröffentlicht 03.03.2023 23:15:12
- Zuletzt bearbeitet 21.11.2024 07:52:35
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/wr...
1