VYPR
Unrated severityNVD Advisory· Published Nov 19, 2018· Updated Sep 17, 2024

CVE-2018-1841

CVE-2018-1841

Description

IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150901.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Cloud Private 2.1.0 exposes the CA private key to local users due to world-readable permissions on the boot/master node.

Vulnerability

IBM Cloud Private 2.1.0 stores the Certificate Authority (CA) private key in the /etc/cfc directory on the boot/master node. The file permissions are not sufficiently restricted, making the key world-readable. This affects all installations of version 2.1.0. [1]

Exploitation

A local user with access to the boot/master node can read the CA private key by navigating to the /etc/cfc directory. No authentication beyond local login is required, as the file is world-readable. The attacker does not need special privileges or user interaction. [1]

Impact

Successful exploitation allows an attacker to obtain the CA private key, which can be used to decrypt sensitive communications or impersonate trusted services within the IBM Cloud Private environment. This constitutes a high confidentiality impact, with no impact on integrity or availability. [1]

Mitigation

IBM has released version 3.1.0 (and higher) which includes the fix. Users of 2.1.0.x should upgrade to 3.1.0 or later, available from IBM Passport Advantage. As a workaround, administrators can set file system permissions manually: chmod 0700 for all directories under /etc/cfc and chmod 0600 for all files under /etc/cfc. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.