CVE-2016-0202Sensitive Information Exposure in Corporation Cloud Orchestrator

Severity
3.3LOWNVD
EPSS
0.1%
top 82.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateMay 17

Description

A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/cloud_orchestrator6 versions+5
CVEListV5ibm_corporation/cloud_orchestrator11 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rr3j-c9jc-fvc3: A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator2022-05-17
CVEList
CVE-2016-0202: A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator2017-02-08

🕵️Threat Intelligence

1
Talos
Vulnerability Spotlight: Iceni Argus Buffer Overflows2016-10-26
CVE-2016-0202 — Sensitive Information Exposure | cvebase