VYPR

Cloud Orchestrator Enterprise

by IBM

CVEs (3)

  • CVE-2019-4397MedOct 24, 2019
    risk 0.42cvss 6.5epss 0.01

    IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or…

  • CVE-2019-4459MedOct 24, 2019
    risk 0.35cvss 5.4epss 0.01

    IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…

  • CVE-2019-4398LowOct 24, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.