Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cloud orchestrator vulnerabilities and exploits
(subscribe to this query)
2.1
CVSSv2
CVE-2016-0202
A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.
Ibm Cloud Orchestrator 2.4
Ibm Cloud Orchestrator 2.4.0.1
Ibm Cloud Orchestrator 2.4.0.2
Ibm Cloud Orchestrator 2.4.0.3
Ibm Cloud Orchestrator 2.3
Ibm Cloud Orchestrator 2.3.0.1
2.1
CVSSv2
CVE-2016-0203
A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects where the user belongs to.
Ibm Smartcloud Orchestrator 2.3
Ibm Cloud Orchestrator 2.5
Ibm Cloud Orchestrator 2.5.01
Ibm Cloud Orchestrator 2.4
Ibm Cloud Orchestrator 2.4.0.1
Ibm Cloud Orchestrator 2.4.0.2
Ibm Smartcloud Orchestrator 2.3.0.1
Ibm Cloud Orchestrator 2.4.0.3
1.7
CVSSv2
CVE-2015-7494
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain acce...
Ibm Cloud Orchestrator 2.4.0.3
Ibm Cloud Orchestrator 2.5
Ibm Cloud Orchestrator 2.5.01
Ibm Cloud Orchestrator 2.4
Ibm Cloud Orchestrator 2.4.0.2
Ibm Smartcloud Orchestrator 2.3
Ibm Smartcloud Orchestrator 2.3.0.1
Ibm Cloud Orchestrator 2.4.0.1
2.1
CVSSv2
CVE-2016-0206
IBM Cloud Orchestrator could allow a local authenticated malicious user to cause the server to slow down for a short period of time by using a specially crafted and malformed URL.
Ibm Cloud Orchestrator 2.4.0.1
Ibm Cloud Orchestrator 2.4.0.2
Ibm Cloud Orchestrator 2.3
Ibm Cloud Orchestrator 2.3.0.1
Ibm Cloud Orchestrator 2.4
2.1
CVSSv2
CVE-2016-0205
A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacker after authentication to enumerate valid users of the system. IBM X-Force ID: 109394.
Ibm Cloud Orchestrator 2.4.0.0
Ibm Cloud Orchestrator 2.4.0.1
Ibm Cloud Orchestrator 2.3.0.1
Ibm Cloud Orchestrator 2.3.0.0
5.8
CVSSv2
CVE-2016-0204
Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x prior to 2.4.0 FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Ibm Cloud Orchestrator 2.4.0.0
Ibm Cloud Orchestrator 2.4.0.2
Ibm Cloud Orchestrator 2.4.0.1
2.1
CVSSv2
CVE-2019-4398
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 up to and including 2.5.0.9 and 2.4 up to and including 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.
Ibm Cloud Orchestrator
Ibm Cloud Orchestrator Enterprise
4
CVSSv2
CVE-2019-4397
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 up to and including 2.5.0.9 and 2.4 up to and including 2.4.0.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs...
Ibm Cloud Orchestrator Enterprise
Ibm Cloud Orchestrator
2.1
CVSSv2
CVE-2019-4394
IBM Cloud Orchestrator 2.4 up to and including 2.4.0.5 and 2.5 up to and including 2.5.0.9 contain APIs that could be used by a local user to send email. IBM X-Force ID: 162232.
Ibm Cloud Orchestrator
2.1
CVSSv2
CVE-2019-4395
IBM Cloud Orchestrator 2.4 up to and including 2.4.0.5 and 2.5 up to and including 2.5.0.9 could allow a local user to obtain sensitive information from temporary script files. IBM X-Force ID: 162333.
Ibm Cloud Orchestrator
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »