CVE-2018-1000627

CRITICAL

Battelle V2I Hub 2.5.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to the API key file. An attacker could exploit this vulnerability to obtain the current API key to gain unauthorized access to the system.

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/147304

Scores

CVSS v3 9.8
EPSS 0.0228
EPSS Percentile 80.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (1)
battelle/v2i_hub 2.5.1
Published Dec 28, 2018
Tracked Since Feb 18, 2026