VYPR
Low severity2.8NVD Advisory· Published Feb 8, 2017· Updated May 13, 2026

CVE-2015-7494

CVE-2015-7494

Description

A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.

Affected products

1
  • IBM Corporation/Cloud Orchestratorv5
    Range: 2.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.