CVE-2019-4394Improper Input Validation in IBM Cloud Orchestrator

Severity
2.3LOWNVD
EPSS
0.1%
top 73.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Latest updateMay 24

Description

IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 contain APIs that could be used by a local user to send email. IBM X-Force ID: 162232.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 0.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/cloud_orchestrator2.4.0.02.4.0.5+1
CVEListV5ibm/cloud_orchestrator16 versions+15

🔴Vulnerability Details

2
GHSA
GHSA-f5g2-85rj-5g35: IBM Cloud Orchestrator 22022-05-24
CVEList
CVE-2019-4394: IBM Cloud Orchestrator 22019-10-25

💬Community

1
Bugzilla
CVE-2019-1010091 tinymce: cross site scripting in media element2019-07-18
CVE-2019-4394 — Improper Input Validation in IBM | cvebase