CVE-2019-4399Use of a Broken or Risky Cryptographic Algorithm in IBM Cloud Orchestrator

Severity
7.5HIGHNVD
EPSS
0.1%
top 66.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Latest updateMay 24

Description

IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 162260.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDibm/cloud_orchestrator2.4.0.02.4.0.5+1
CVEListV5ibm/cloud_orchestrator16 versions+15

🔴Vulnerability Details

2
GHSA
GHSA-fjgm-pj6m-hwxx: IBM Cloud Orchestrator 22022-05-24
CVEList
CVE-2019-4399: IBM Cloud Orchestrator 22019-10-25
CVE-2019-4399 — IBM Cloud Orchestrator vulnerability | cvebase