CVE-2023-37404: IBM Observability With Instana

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789.

Affected products

  • IBM Observability With Instana: from 1.0.243, before 1.0.255 (fixed in 1.0.255)

Published 2023-10-04. Last modified 2026-06-17.