Impact
IBM Observability with Instana Agent is vulnerable to prototype pollution in the @instana/core configuration normalization API. The flaw allows an attacker who can supply configuration data to modify JavaScript object prototypes, potentially changing program behavior or state. This weakness is classified as CWE-1321 and rated with a CVSS score of 7.3, indicating a high severity impact primarily on data integrity and confidentiality.
Affected Systems
IBM Observability with Instana Agent from Build 1.0.303 through 1.0.320 is affected. The vulnerable component is @instana/core version 6.2.1 used in the Agent.
Risk and Exploitability
The EPSS score of less than 1 % indicates a low likelihood of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be through configuration data supplied to the Agent’s normalization routine, which could be via internal configuration services or exposed APIs. An attacker who can influence this input could alter the Agent’s execution context or data, but the CVE description does not state that arbitrary code execution is possible. The high CVSS score still warrants prompt remediation.
OpenCVE Enrichment