Jan 18, 2019 9:00 am EST
Categorized: Medium Severity
Share this post:
PowerVC has addressed the following vulnerability. An authenticated “GET /v3/OS-FEDERATION/projects” request to the identity API may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes.
CVE(s): CVE-2018-14432
Affected product(s) and affected version(s):
| Affected Product | Affected Versions |
| IBM PowerVC Standard | 1.3.3 |
| IBM PowerVC Standard | 1.4.0 |
| IBM PowerVC Standard | 1.4.1 |
| IBM Cloud PowerVC Manager | 1.3.3 |
| IBM Cloud PowerVC Manager | 1.4.0 |
| IBM Cloud PowerVC Manager | 1.4.1 |
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10794471
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/147412
from IBM Product Security Incident Response Team https://ibm.co/2HkqL1f
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.