PT-2019-2402 · Intel · Open Cloud Integrity Technology+1

Published

2019-06-11

·

Updated

2023-02-27

·

CVE-2019-0181

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Cloud Integrity Technology (affected versions not specified) OpenAttestation (affected versions not specified)
Description The issue is related to errors in input validation in Open Cloud Integrity Technology and OpenAttestation. It may allow an attacker to elevate privileges using a specially crafted request. Insufficient password protection in the attestation database for Open CIT may enable information disclosure via local access for authenticated users.
Recommendations For Open Cloud Integrity Technology, consider restricting access to the attestation database to minimize the risk of information disclosure. For OpenAttestation, as a temporary workaround, consider disabling local access to the attestation database until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2019-02178
CVE-2019-0181

Affected Products

Open Cloud Integrity Technology
Openattestation