Cloud Orchestrator
Vendor:
First CVE: Oct 16, 2016 · Active for 9 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
4.6
Avg CVSS
Higher Avg CVSS than 5% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloud Orchestrator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2016
9 years ago
Most Recent CVE
Oct 25, 2019
2,463 days ago
CVE Severity & Scoring
Cloud Orchestrator15 CVEs
47%
47%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local8 (53.3%)
Network7 (46.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High1 (6.7%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low13 (86.7%)
High1 (6.7%)
None1 (6.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-4399HIGH IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive infor | Oct 25, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-4397MEDIUM IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitive information in URL parameters. This may lead to informatio | Oct 24, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-4461MEDIUM IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to | Oct 25, 2019 | 5.4 | 19 | NO | NO |
CVE-2019-4396MEDIUM IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote | Oct 25, 2019 | 5.4 | 19 | NO | NO |
CVE-2016-0204MEDIUM Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x before 2.4.0 FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks | Oct 16, 2016 | 6.8 | 19 | NO | NO |
CVE-2019-4459MEDIUM IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to e | Oct 24, 2019 | 5.4 | 18 | NO | NO |
CVE-2019-4400MEDIUM IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted U | Oct 25, 2019 | 4.3 | 17 | NO | NO |
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a local user to obtain sensitive information from temporary script files. IBM X-Force ID: 162333. | Oct 25, 2019 | 3.3 | 16 | NO | NO |
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManage | Oct 24, 2019 | 3.3 | 16 | NO | NO |
IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL. | Feb 8, 2017 | 3.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Cloud Orchestrator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5.01 | 2 | 4.2 | 0.3% | 0 | 0 |
| 2.5 | 2 | 4.2 | 0.3% | 0 | 0 |
| 2.4.0.3 | 3 | 3.9 | 0.3% | 0 | 0 |
| 2.4.0.2 | 5 | 4.3 | 0.5% | 0 | 0 |
| 2.4.0.1 | 6 | 4.2 | 0.4% | 0 | 0 |
| 2.4.0.0 | 2 | 5.0 | 0.7% | 0 | 0 |
| 2.4 | 4 | 3.7 | 0.3% | 0 | 0 |
| 2.3.0.1 | 3 | 3.3 | 0.3% | 0 | 0 |
| 2.3.0.0 | 1 | 3.3 | 0.4% | 0 | 0 |
| 2.3 | 2 | 3.3 | 0.3% | 0 | 0 |