PT-2019-17060 · Ibm · Ibm Cloud Orchestrator+1

Published

2019-10-24

·

Updated

2019-10-30

·

CVE-2019-4397

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise versions 2.4 through 2.4.0.5 IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise versions 2.5 through 2.5.0.9
Description The issue concerns the storage of sensitive information in URL parameters, which may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, or browser history.
Recommendations For versions 2.4 through 2.4.0.5, consider restricting access to server logs and referrer headers to minimize the risk of exploitation. For versions 2.5 through 2.5.0.9, consider implementing measures to protect sensitive information in URL parameters, such as encrypting the data or using alternative methods for storing and transmitting sensitive information. As a temporary workaround, consider disabling the use of sensitive information in URL parameters until a more permanent solution is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-4397

Affected Products

Ibm Cloud Orchestrator
Ibm Cloud Orchestrator Enterprise