Description
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
4.0
References
www.ibm.com/support/pages/node/6999351
exchange.xforce.ibmcloud.com/vulnerabilities/247905
www.ibm.com/support/pages/node/6999351
exchange.xforce.ibmcloud.com/vulnerabilities/247905