First published: Wed Feb 03 2021(Updated: )
IBM Business Automation Insights stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user with permissions to read log files.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Automation | =20.0.2-interim_fix002 | |
IBM Cloud Pak for Automation | =20.0.3 | |
<=20.0.3 | ||
<=20.0.2 IF002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-20358.
The severity of CVE-2021-20358 is medium (severity value: 6.5).
The affected software for CVE-2021-20358 is IBM Cloud Pak for Automation versions 20.0.3 and 20.0.2-IF002.
CVE-2021-20358 allows potentially sensitive information to be stored in clear text in API connection log files, which can be accessed by users with log file read permissions.
Yes, you can find more information on CVE-2021-20358 at the following references: [IBM X-Force ID: 194965](https://exchange.xforce.ibmcloud.com/vulnerabilities/194965) and [IBM Support Page](https://www.ibm.com/support/pages/node/6412345).