Security Advisory

CVE-2015-7494

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-02-08 22:00:00
Last updated 2024-08-06 07:51:28
Assigner ibm
CVSS score not scored
State PUBLISHED

Description

A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.