Vulnerability Name: | CVE-2016-0203 (CCN-109391) | ||||||||||||
Assigned: | 2015-12-08 | ||||||||||||
Published: | 2016-11-18 | ||||||||||||
Updated: | 2017-02-15 | ||||||||||||
Summary: | A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects where the user belongs to. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-0203 Source: CCN Type: IBM Security Bulletin C1000140 (Cloud Orchestrator) Vulnerabilities in IBM Cloud Orchestrator (CVE-2016-0203, CVE-2015-7494) Source: CONFIRM Type: Patch, Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg2C1000140 Source: BID Type: Third Party Advisory, VDB Entry 94440 Source: CCN Type: BID-94440 Multiple IBM Products CVE-2016-0203 Local Information Disclosure Vulnerability Source: XF Type: UNKNOWN ibm-co-cve20160203-info-disc(109391) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |