VulnerabilityModified
CVE-2019-4335
IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user.
MEDIUM 5.5EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- ibm/watson studio local
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/161413VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/1146370Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/161413VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/1146370Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.