VulnerabilityModified
CVE-2018-1843
It could be possible for an attacker with access to network traffic to sniff packets from the connection and uncover data.
MEDIUM 4.1EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster. It could be possible for an attacker with access to network traffic to sniff packets from the connection and uncover data. IBM X-Force ID: 150903
- CVSS 3.0
- 4.1 MEDIUMCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/cloud private
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=ibm10739845Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/150903VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10739845Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/150903VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.