VYPR

Observability With Instana

by IBM

CVEs (5)

  • CVE-2023-27290CriMar 3, 2023
    risk 0.63cvss 9.1epss 0.09

    Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: …

  • CVE-2026-19274CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed…

  • CVE-2026-19283HigSep 4, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the…

  • CVE-2023-37404MedOct 4, 2023
    risk 0.42cvss 6.4epss 0.01

    IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789.

  • CVE-2026-14893HigJul 28, 2026
    risk 0.00cvss 7.3epss 0.00

    IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.