CVE-2019-4415
Description
IBM Cloud Private 3.1.1 and 3.1.2 could allow a local user to obtain elevated privileges due to improper security context constraints. IBM X-Force ID: 162706.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Cloud Private 3.1.1/3.1.2 on OpenShift misassigns the icp-scc SecurityContextConstraint to all pods, allowing local privilege escalation.
Vulnerability
IBM Cloud Private versions 3.1.1 and 3.1.2, when deployed on OpenShift clusters, improperly assign the icp-scc SecurityContextConstraint (SCC) to pods in all namespaces. This occurs for pods managed by Deployments, StatefulSets, DaemonSets, Jobs, and other controllers, regardless of the user ID used to create the resource or the service account assigned to the pod [1].
Exploitation
An attacker with local access to the cluster can exploit the misconfigured SCC to run pods with elevated privileges. The icp-scc SCC is erroneously applied via the SCC's group membership, allowing any pod to inherit its permissions without needing specific user or service account associations [1].
Impact
Successful exploitation allows a local user to obtain elevated privileges, potentially leading to limited confidentiality, integrity, and availability impacts (CVSS 4.9, vector AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L) [1].
Mitigation
IBM recommends applying the following kubectl commands on the master node to restrict icp-scc to only authorized service accounts:
kubectl patch scc icp-scc --type='json' -p='[{"op": "remove", "path": "/groups"}]'
kubectl patch scc icp-scc --type='json' -p='[{"op": "add", "path": "/users", "value": ["system:serviceaccount:kube-system:default","system:serviceaccount:istio-system:default", "system:serviceaccount:icp-system:default","system:serviceaccount:cert-manager:default"]}]'
This fix removes group-level access and explicitly grants the SCC to specific system service accounts. No workaround is provided beyond this remediation [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=3.1.2
- IBM/Cloud Privatev5Range: 3.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
- exchange.xforce.ibmcloud.com/vulnerabilities/162706mitrevdb-entryx_refsource_XF
News mentions
0No linked articles in our index yet.