CVE-2023-27290

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
03/03/2023
Last modified:
10/04/2023

Description

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:observability_with_instana:*:*:*:*:*:*:*:* 239-0 (including) 239-2 (including)
cpe:2.3:a:ibm:observability_with_instana:*:*:*:*:*:*:*:* 241-0 (including) 241-2 (including)
cpe:2.3:a:ibm:observability_with_instana:243-0:*:*:*:*:*:*:*