Cloud Private
Vendor:
First CVE: Nov 19, 2018 · Active for 7 years
16
Total CVEs
More Total CVEs than 92% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloud Private over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2018
7 years ago
Most Recent CVE
Aug 20, 2019
2,531 days ago
CVE Severity & Scoring
Cloud Private16 CVEs
81%
19%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local10 (62.5%)
Network6 (37.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None11 (68.8%)
Unknown0 (0.0%)
Required5 (31.3%)
Privileges Required
Low8 (50.0%)
High4 (25.0%)
None4 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-4142HIGH IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted | Jun 18, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-4117HIGH IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user th | Aug 20, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-4415HIGH IBM Cloud Private 3.1.1 and 3.1.2 could allow a local user to obtain elevated privileges due to improper security context constraints. IBM X-Force ID: 162706. | Jul 25, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-1939MEDIUM IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a re | Mar 5, 2019 | 6.1 | 22 | NO | NO |
CVE-2019-4239MEDIUM IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465. | Jun 14, 2019 | 5.5 | 21 | NO | NO |
CVE-2019-4120MEDIUM IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended | Aug 20, 2019 | 5.4 | 20 | NO | NO |
CVE-2019-4439MEDIUM IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 162949. | Jul 25, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-4143MEDIUM The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log. IBM X-Force ID: 158 | Apr 8, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-1943MEDIUM IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, | Apr 8, 2019 | 5.4 | 20 | NO | NO |
CVE-2018-1841MEDIUM IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150901. | Nov 19, 2018 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Cloud Private
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1.2 | 7 | 6.6 | 0.5% | 0 | 0 |
| 3.1.1 | 12 | 6.0 | 0.6% | 0 | 0 |
| 3.1.0 | 8 | 6.0 | 0.6% | 0 | 0 |
| 2.1.0 | 2 | 5.5 | 0.4% | 0 | 0 |