#VU72762 Missing Authentication for Critical Function in IBM Observability with Instana - CVE-2023-27290


| Updated: 2024-10-25

Vulnerability identifier: #VU72762

Vulnerability risk: High

CVSSv4.0: 8.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber]

CVE-ID: CVE-2023-27290

CWE-ID: CWE-306

Exploitation vector: Network

Exploit availability: Yes

Vulnerable software:
IBM Observability with Instana
Server applications / Other server solutions

Vendor: IBM Corporation

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to docker based datastores for IBM Instana do not currently require authentication. A remote attacker can compromise the affected systsem.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

IBM Observability with Instana: 239-0 - 243-0


External links
https://www.ibm.com/support/pages/node/6959969
https://exchange.xforce.ibmcloud.com/vulnerabilities/248737


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability