CVE-2023-27877
published 2023-07-19CVE-2023-27877: IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.46%
37.2th percentile
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cloud_pak_for_data | — | — |
| ibm | planning_analytics_cartridge_for_cloud_pak_for_data | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qw89-4pf3-xh2c: IBM Planning Analytics Cartridge for Cloud Pak for Data 4
ghsa_unreviewed·2023-07-19
CVE-2023-27877 [HIGH] CWE-200 GHSA-qw89-4pf3-xh2c: IBM Planning Analytics Cartridge for Cloud Pak for Data 4
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
CISA
Veritas Backup Exec Agent Improper Authentication Vulnerability
cisa·2023-04-07·CVSS 9.8
CVE-2021-27877 [HIGH] CWE-287 Veritas Backup Exec Agent Improper Authentication Vulnerability
Vulnerability: Veritas Backup Exec Agent Improper Authentication Vulnerability
Affected: Veritas Backup Exec Agent
Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.
Required Action: Apply updates per vendor instructions.
Notes: https://www.veritas.com/support/en_US/security/VTS21-001; https://nvd.nist.gov/vuln/detail/CVE-2021-27877
Remediation Due Date: 2023-04-28
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-19
Published