Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qw89-4pf3-xh2c

Опубликовано: 19 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.

EPSS

Процентиль: 18%
0.00059
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-287

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.

EPSS

Процентиль: 18%
0.00059
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-287