Cloud Private

Vendor:

First CVE: Nov 19, 2018 · Active for 7 years

16
Total CVEs
More Total CVEs than 92% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cloud Private over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2018
7 years ago
Most Recent CVE
Aug 20, 2019
2,531 days ago

CVE Severity & Scoring

Cloud Private16 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local10 (62.5%)
Network6 (37.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None11 (68.8%)
Unknown0 (0.0%)
Required5 (31.3%)
Privileges Required
Low8 (50.0%)
High4 (25.0%)
None4 (25.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted
Jun 18, 20198.827NONO
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user th
Aug 20, 20198.826NONO
IBM Cloud Private 3.1.1 and 3.1.2 could allow a local user to obtain elevated privileges due to improper security context constraints. IBM X-Force ID: 162706.
Jul 25, 20197.825NONO
IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a re
Mar 5, 20196.122NONO
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
Jun 14, 20195.521NONO
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended
Aug 20, 20195.420NONO
IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 162949.
Jul 25, 20195.320NONO
The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log. IBM X-Force ID: 158
Apr 8, 20195.520NONO
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page,
Apr 8, 20195.420NONO
IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150901.
Nov 19, 20185.520NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Cloud Private

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.1.276.60.5%00
3.1.1126.00.6%00
3.1.086.00.6%00
2.1.025.50.4%00