Impact
IBM Documentation Offline 1.0.0 through 1.4.1 contains a security misconfiguration that causes the documentation server to bind to an unrestricted IP address, allowing a remote attacker to obtain sensitive information. The vulnerability can also be exploited for session forgery and potentially remote code execution if an attacker manipulates the server environment, although the official description focuses on data disclosure.
Affected Systems
The affected product is IBM Documentation Offline, versions 1.0.0 through 1.4.1. The bug is present in all releases within that range and has been addressed in version 1.5.1.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available, suggesting limited data on exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the server binding misconfiguration, the likely attack vector is a remote attacker who can reach the documentation server over the network, potentially exploiting unrestricted access to sensitive data and session tokens.
OpenCVE Enrichment