CVE-2015-7494
2.8
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Exploitability: 1.1 / Impact: 1.4
Source: NVD
Description
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.
Affected (8)
Products: Ibm: Cloud Orchestrator, Smartcloud Orchestrator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.4.0.1 | |
| Version 2.3.0.1 |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.