CVE-2021-20358: Medium severity IBM Cloud Pak for Automation vulnerability
IBM Business Automation Insights stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user with permissions to read log files.
Other sources
IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user with permissions to read log files. IBM X-Force ID: 194965.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-20358.
What is the severity of CVE-2021-20358?
The severity of CVE-2021-20358 is medium (severity value: 6.5).
What is the affected software for CVE-2021-20358?
The affected software for CVE-2021-20358 is IBM Cloud Pak for Automation versions 20.0.3 and 20.0.2-IF002.
How does CVE-2021-20358 impact security?
CVE-2021-20358 allows potentially sensitive information to be stored in clear text in API connection log files, which can be accessed by users with log file read permissions.
Are there any references for more information on CVE-2021-20358?
Yes, you can find more information on CVE-2021-20358 at the following references: [IBM X-Force ID: 194965](https://exchange.xforce.ibmcloud.com/vulnerabilities/194965) and [IBM Support Page](https://www.ibm.com/support/pages/node/6412345).