CVE-2023-40694Log File Information Exposure in IBM Watson Cp4d Data Stores

Severity
5.5MEDIUMNVD
CNA6.2
EPSS
0.0%
top 89.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 7

Description

IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/watson_cp4d_data_stores4.0.04.8.5
CVEListV5ibm/watson_cp4d_data_stores4.0.04.8.4

🔴Vulnerability Details

2
GHSA
GHSA-fc6m-c8v2-74q6: IBM Watson CP4D Data Stores 42024-05-07
CVEList
IBM Watson CP4D Data Stores information disclosure2024-05-07
CVE-2023-40694 — Log File Information Exposure in IBM | cvebase