First published: Wed Feb 03 2021(Updated: )
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user on the network to cause a denial of service due to an invalid cookie value that could prevent future logins. IBM X-Force ID: 196078.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Information Queue | <=1.0.6, 1.0.7 | |
IBM Security Verify Information Queue | =1.0.6 | |
IBM Security Verify Information Queue | =1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20404 is a vulnerability in IBM Security Verify Information Queue 1.0.6 and 1.0.7 that could allow a user on the network to cause a denial of service by sending an invalid cookie value.
CVE-2021-20404 affects IBM Security Verify Information Queue versions 1.0.6 and 1.0.7.
The severity of CVE-2021-20404 is medium, with a CVSS score of 5.3.
An attacker can exploit CVE-2021-20404 by sending an invalid cookie value, which could cause a denial of service and prevent future logins.
More information about CVE-2021-20404 can be found at the following references: [IBM X-Force ID 196078](https://exchange.xforce.ibmcloud.com/vulnerabilities/196078) and [IBM support page](https://www.ibm.com/support/pages/node/6414363).