Vulnerabilities > IBM > Cloud Private

DATE CVE VULNERABILITY TITLE RISK
2019-04-08 CVE-2018-1943 Injection vulnerability in IBM Cloud Private 3.1.0/3.1.1
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input.
network
ibm CWE-74
3.5
2019-03-05 CVE-2018-1939 Open Redirect vulnerability in IBM Cloud Private 3.1.1
IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
ibm CWE-601
5.8
2019-03-05 CVE-2018-1938 Missing Encryption of Sensitive Data vulnerability in IBM Cloud Private 3.1.1
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data.
local
low complexity
ibm CWE-311
2.1
2019-03-05 CVE-2018-1937 Missing Encryption of Sensitive Data vulnerability in IBM Cloud Private 3.1.1
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data.
local
low complexity
ibm CWE-311
2.1
2018-11-21 CVE-2018-1843 Information Exposure vulnerability in IBM Cloud Private 3.1.0
The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster.
local
ibm CWE-200
1.9
2018-11-19 CVE-2018-1841 Information Exposure vulnerability in IBM Cloud Private 2.1.0
IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node.
local
low complexity
ibm CWE-200
2.1