Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm cloud orchestrator 2.5 vulnerabilities and exploits
(subscribe to this query)
187
VMScore
CVE-2016-0203
A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects where the user belongs to.
Ibm Smartcloud Orchestrator 2.3
Ibm Cloud Orchestrator 2.5
Ibm Cloud Orchestrator 2.5.01
Ibm Cloud Orchestrator 2.4
Ibm Cloud Orchestrator 2.4.0.1
Ibm Cloud Orchestrator 2.4.0.2
Ibm Smartcloud Orchestrator 2.3.0.1
Ibm Cloud Orchestrator 2.4.0.3
151
VMScore
CVE-2015-7494
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain acce...
Ibm Cloud Orchestrator 2.4.0.3
Ibm Cloud Orchestrator 2.5
Ibm Cloud Orchestrator 2.5.01
Ibm Cloud Orchestrator 2.4
Ibm Cloud Orchestrator 2.4.0.2
Ibm Smartcloud Orchestrator 2.3
Ibm Smartcloud Orchestrator 2.3.0.1
Ibm Cloud Orchestrator 2.4.0.1
187
VMScore
CVE-2019-4398
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 up to and including 2.5.0.9 and 2.4 up to and including 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.
Ibm Cloud Orchestrator
Ibm Cloud Orchestrator Enterprise
356
VMScore
CVE-2019-4397
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 up to and including 2.5.0.9 and 2.4 up to and including 2.4.0.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs...
Ibm Cloud Orchestrator Enterprise
Ibm Cloud Orchestrator
187
VMScore
CVE-2019-4394
IBM Cloud Orchestrator 2.4 up to and including 2.4.0.5 and 2.5 up to and including 2.5.0.9 contain APIs that could be used by a local user to send email. IBM X-Force ID: 162232.
Ibm Cloud Orchestrator
187
VMScore
CVE-2019-4395
IBM Cloud Orchestrator 2.4 up to and including 2.4.0.5 and 2.5 up to and including 2.5.0.9 could allow a local user to obtain sensitive information from temporary script files. IBM X-Force ID: 162333.
Ibm Cloud Orchestrator
445
VMScore
CVE-2019-4399
IBM Cloud Orchestrator 2.4 up to and including 2.4.0.5 and 2.5 up to and including 2.5.0.9 uses weaker than expected cryptographic algorithms that could allow an malicious user to decrypt highly sensitive information. IBM X-Force ID: 162260.
Ibm Cloud Orchestrator
356
VMScore
CVE-2019-4400
IBM Cloud Orchestrator 2.4 up to and including 2.4.0.5 and 2.5 up to and including 2.5.0.9 could allow a remote malicious user to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arb...
Ibm Cloud Orchestrator
312
VMScore
CVE-2019-4461
IBM Cloud Orchestrator 2.4 up to and including 2.4.0.5 and 2.5 up to and including 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the malicious user to perform further attacks, such as Web Cache poisoning, cross-site scrip...
Ibm Cloud Orchestrator
312
VMScore
CVE-2019-4459
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 up to and including 2.5.0.9 and 2.4 up to and including 2.4.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended func...
Ibm Cloud Orchestrator
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »