Lucene search

K
ibmIBM5149CDF35E7BA9ABAB03C9A07BE3AA46B6CC84C1E1209372C975F1E8258BBB19
HistoryJun 14, 2019 - 9:30 p.m.

Security Bulletin: IBM Cloud Private Platform-UI is vulnerable to a cross-site request forgery attack (CVE-2019-4142)

2019-06-1421:30:02
www.ibm.com
8

EPSS

0.001

Percentile

26.1%

Summary

IBM Cloud Private Platform-UI is vulnerable to a cross-site request forgery attack

Vulnerability Details

CVEID: CVE-2019-4142 DESCRIPTION: IBM Cloud Private is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/158338&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)

Affected Products and Versions

IBM Cloud Private 2.1.x, 3.1.0, 3.1.1, 3.1.2

Remediation/Fixes

Product defect fixes and security updates are only available for the two most recent Continuous Delivery (CD) update packages

  • IBM Cloud Private 3.1.2
  • IBM Cloud Private 3.1.1

For IBM Cloud Private 3.1.2, apply patch:

For IBM Cloud Private 3.1.1, apply patch:

For IBM Cloud Private, 2.1.x, 3.1.0:

  • Upgrade to the latest Continuous Delivery (CD) update package, IBM Cloud Private 3.2.
  • If required, individual product fixes can be made available between CD update packages for resolution of problems. Contact IBM support for assistance

Workarounds and Mitigations

None

EPSS

0.001

Percentile

26.1%

Related for 5149CDF35E7BA9ABAB03C9A07BE3AA46B6CC84C1E1209372C975F1E8258BBB19