Lucene search

K
ibmIBM58CCF2E0707DEE78521FA709AF14E44C8BB9A2480A17F468FE20AE159D0FDC25
HistoryMar 22, 2023 - 10:39 p.m.

Security Bulletin: IBM Watson CloudPak for Data Data Stores are vulnerable to web pages stored locally which can be read by another user on the system

2023-03-2222:39:30
www.ibm.com
10
ibm watson
cp4d data stores
vulnerability
web pages
local access
user system
cve-2023-27545
cvss
pre-4.6.3
datastores
version 4.6.1

CVSS3

4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0

Percentile

9.0%

Summary

IBM Watson CP4D Data Stores allows web pages to be stored locally which can be read by another user on the system.

Vulnerability Details

CVEID:CVE-2023-27545
**DESCRIPTION:**IBM Watson CP4D Data Stores allows web pages to be stored locally which can be read by another user on the system.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/248947 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Watson CloudPak for Data Data Stores pre-4.6.3

Remediation/Fixes

Use of Watson CloudPak for Data datastores after Version 4.6.1
<https://www.ibm.com/docs/en/cloud-paks/cp-data/4.6.x&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmwatson_developer_cloudMatch4.6.3
VendorProductVersionCPE
ibmwatson_developer_cloud4.6.3cpe:2.3:a:ibm:watson_developer_cloud:4.6.3:*:*:*:*:*:*:*

CVSS3

4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0

Percentile

9.0%

Related for 58CCF2E0707DEE78521FA709AF14E44C8BB9A2480A17F468FE20AE159D0FDC25