CVE-2019-4284
Description
IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to the system as another user. IBM X-Force ID: 160512.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Cloud Private logs OIDC tokens in ingress logs, letting local privileged users obtain tokens to impersonate other users.
Vulnerability
IBM Cloud Private versions 2.1.x, 3.1.0, 3.1.1, and 3.1.2 contain a vulnerability where OpenID Connect (OIDC) tokens are written to ingress log files [1]. These tokens could be accessed by a local user with elevated privileges, enabling them to authenticate as another user. The issue arises from improper handling of sensitive information in log output.
Exploitation
An attacker must have local privileged access to the IBM Cloud Private system, typically requiring administrative rights on the host or container running the ingress component [1]. The exploit involves reading the ingress log files to extract OIDC tokens that were inadvertently logged during normal operation. No user interaction is needed beyond the attacker's existing privileges.
Impact
A successful attacker can use the obtained OIDC token to log in to the system as another user, leading to unauthorized access and potential escalation of privileges within the IBM Cloud Private environment [1]. The confidentiality impact is high, but integrity and availability are not directly affected.
Mitigation
IBM has released patches for versions 3.1.1 and 3.1.2 under the icp-management-ingress fix. For version 2.1.x, IBM recommends upgrading to the latest Continuous Delivery (CD) update package version 3.2.0 [1]. No workarounds are available. Users should apply the appropriate patch or upgrade immediately.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2.1.0, 3.1.0, 3.1.1, 3.1.2
- IBM/Cloud Privatev5Range: 2.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/160512mitrevdb-entryx_refsource_XF
- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.