Home » Database

AVID-2026-R1276

Description

IBM Watson CP4D Data Stores information disclosure (CVE-2023-40694)

Details

IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838.

Reason for inclusion in AVID: CVE-2023-40694 describes an information-disclosure vulnerability in IBM Watson CP4D Data Stores where sensitive data could be written to log files and read by a local user. This is a software vulnerability (security/confidentiality) in a component (Data Stores) that is used within AI data platforms and pipelines, making it relevant to general-purpose AI system stacks. It affects software used to build/train/deploy AI workloads, thus relevant to the AI supply chain. The CVE provides explicit details (CWE-532, log file leakage) and references, satisfying evidence requirements.

References

Affected or Relevant Artifacts

  • Developer: IBM
  • Deployer: IBM
  • Artifact Details:
TypeName
SystemWatson CP4D Data Stores

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score6.2
Base Severity🟠 Medium
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity ImpactNONE
Availability ImpactNONE

CWE

IDDescription
CWE-532CWE-532 Insertion of Sensitive Information into Log File

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-05-07
  • Version: 0.3.3
  • AVID Entry