Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6959969 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/248737 | vdb entry vendor advisory |
http://packetstormsecurity.com/files/171770/IBM-Instana-243-0-Missing-Authentication.html |