Information disclosure in console - CVE-2023-33955
Published: October 26, 2023
Vulnerability identifier: #VU82450
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33955
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
console
IBM Cloud Pak for Watson AIOps
Netcool Operations Insight
IBM Cloud Pak for Watson AIOps
Netcool Operations Insight
How to mitigate CVE-2023-33955
Install updates from vendor's website.
console - update to 0.28.0
Netcool Operations Insight - update to 1.6.10
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Netcool Operations Insight - update to 1.6.10
IBM Cloud Pak for Watson AIOps - update to 4.2.1