Impact
The vulnerability arises from insecure default configurations and hard‑coded credentials in the current development build of Eclipse aeriOS Identity Manager. Exposed Keycloak and PostgreSQL instances are reachable through Kubernetes NodePort services or allow PostgreSQL to listen on all network interfaces. Fixed default credentials provide an attacker with administrative access to the Identity Manager or direct database access. This grants the ability to read, modify, or delete identity‑management data, create privileged identities, or generate tokens that can be accepted by other aeriOS components. The weakness is characterized by multiple CWE IDs such as CWE‑1188 (dangerous default configuration) and CWE‑200 (information exposure).
Affected Systems
The affected product is Eclipse aeriOS (Identity Manager) provided by the Eclipse Foundation. No official release exists yet; the issue is present in the current development version. No specific version numbers are given for the affected shards beyond the product name.
Risk and Exploitability
The CVSS score of 9.9 places this vulnerability in the Critical severity range. The EPSS score is not available, but the lack of protecting controls like secret management and restricted service exposure means an attacker who can reach the exposed services will almost certainly be able to exploit the default credentials. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet, but the risk remains high due to the nature of the exposed services and the administrative power they provide.
OpenCVE Enrichment