vendor:
Instana
by:
Shahid Parvez (zippon)
7.5
CVSS
HIGH
No Authentication
287
CWE
Product Name: Instana
Affected Version From: 239-0
Affected Version To: 243-0
Patch Exists: YES
Related CWE: CVE-2023-27290
CPE: a:ibm:instana:241-2_243-0
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=152474, https://www.infosecmatter.com/nessus-plugin-library/?id=152253, https://www.infosecmatter.com/nessus-plugin-library/?id=152132, https://www.infosecmatter.com/nessus-plugin-library/?id=151723, https://www.infosecmatter.com/nessus-plugin-library/?id=152455, https://www.infosecmatter.com/nessus-plugin-library/?id=153822, https://www.infosecmatter.com/nessus-plugin-library/?id=152272, https://www.infosecmatter.com/nessus-plugin-library/?id=152498, https://www.infosecmatter.com/nessus-plugin-library/?id=157776
Platforms Tested: Mac OS
2023
Exploit Title: Docker based datastores for IBM Instana 241-2 243-0 – No Authentication
This exploit allows an attacker to access the Docker based datastores of IBM Instana 241-2 243-0 without authentication. The exploit is achieved by running various commands on the host using the command line arguments parser. The vulnerable versions are 239-0 to 239-2 241-0 to 241-2 243-0 and the required version is 241-3. The exploit has been tested on Mac OS.
Mitigation:
Upgrade to the required version 241-3 or later.