CVE-2019-4243
published 2019-11-22CVE-2019-4243: IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml and could allow an attacker to perform…
PriorityP417medium4.4CVSS 3.1
AVLACLPRLUINSUCLILAN
EPSS
0.31%
23.3th percentile
IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml and could allow an attacker to perform disruptive administrator tasks. IBM X-Force ID: 159517.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | smartcloud_analytics | — | — |
| ibm | smartcloud_analytics | — | — |
| ibm | smartcloud_analytics | — | — |
| ibm | smartcloud_analytics | — | — |
| ibm | smartcloud_analytics | — | — |
| ibm | smartcloud_analytics_log_analysis | 1.3.1 – 1.3.5 | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19340 Tower: enabling RabbitMQ manager in the installer exposes the management interface publicly
bugzilla·2019-12-12·CVSS 8.2
CVE-2019-19340 [HIGH] CVE-2019-19340 Tower: enabling RabbitMQ manager in the installer exposes the management interface publicly
CVE-2019-19340 Tower: enabling RabbitMQ manager in the installer exposes the management interface publicly
Using '-e rabbitmq_enable_manager=true' in the installer exposes the RabbitMQ management interface publicly with a guessable admin user.
Discussion:
Acknowledgments:
Name: Ryan Petrello (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Ansible Tower 3.5 for RHEL 7
Via RHSA-2019:4242 https://access.redhat.com/errata/RHSA-2019:4242
---
This issue has been addressed in the following products:
Red Hat Ansible Tower 3.6 for RHEL 7
Via RHSA-2019:4243 https://access.redhat.com/errata/RHSA-2019:4243
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-201
Bugzilla
CVE-2019-19341 Tower: intermediate files during Tower backup are world-readable
bugzilla·2019-12-12·CVSS 5.5
CVE-2019-19341 [MEDIUM] CVE-2019-19341 Tower: intermediate files during Tower backup are world-readable
CVE-2019-19341 Tower: intermediate files during Tower backup are world-readable
While a Tower backup is running, files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup, any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower.
Discussion:
Acknowledgments:
Name: Graham Mainwaring (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Ansible Tower 3.5 for RHEL 7
Via RHSA-2019:4242 https://access.redhat.com/errata/RHSA-2019:4242
---
This issue has been addressed in the following products:
Red Hat Ansible Tower 3.6 for RHEL 7
Via RHSA-2019:4243 https://access.redhat.com/errata/RHSA-2019:4243
---
This bug is now closed. Fur
2019-11-22
Published