PT-2018-1933 · Ibm · Ibm Cloud Private

Publicado

2018-11-19

·

Atualizado

2019-10-09

·

CVE-2018-1843

CVSS v3.1

4.1

Média

VetorAV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Private version 3.1.0
Description The issue is related to the Identity and Access Management (IAM) services not using a secure channel, such as SSL, to exchange information when accessed internally from within the cluster. This could allow an attacker with access to network traffic to intercept packets from the connection and uncover sensitive data. The vulnerability is caused by a lack of encryption measures for protected data, which could enable an attacker to disclose sensitive information.
Recommendations For IBM Cloud Private version 3.1.0, consider implementing SSL encryption for internal connections to prevent data interception. As a temporary workaround, restrict access to the IAM services to minimize the risk of exploitation.

Correção

Missing Encryption of Sensitive Data

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01540
CVE-2018-1843

Produtos afetados

Ibm Cloud Private