Lucene search

K
nvd[email protected]NVD:CVE-2023-27291
HistoryMar 03, 2024 - 4:15 p.m.

CVE-2023-27291

2024-03-0316:15:49
CWE-319
web.nvd.nist.gov
2
ibm
watson
cp4d
data stores
encryption
vulnerability
x-force
sensitive information
transmission

CVSS3

4.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

AI Score

4.4

Confidence

High

EPSS

0

Percentile

9.0%

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an attacker to obtain sensitive information. IBM X-Force ID: 248740.

CVSS3

4.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

AI Score

4.4

Confidence

High

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2023-27291