IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and deploy them in the cluster and gain privileges of another user. IBM X-Force ID: 203450.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Event_streams | Ibm | 10.0.0 (including) | 10.0.0 (including) |
Event_streams | Ibm | 10.1.0 (including) | 10.1.0 (including) |
Event_streams | Ibm | 10.2.0 (including) | 10.2.0 (including) |
Event_streams | Ibm | 10.3.0 (including) | 10.3.0 (including) |