First published: Thu Feb 04 2021(Updated: )
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Information Queue | <=1.0.6, 1.0.7 | |
IBM Security Verify Information Queue | =1.0.6 | |
IBM Security Verify Information Queue | =1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-20405 is high with a score of 7.5.
IBM Security Verify Information Queue is a product by IBM that helps manage user identities and access.
Versions 1.0.6 and 1.0.7 of IBM Security Verify Information Queue are affected by CVE-2021-20405.
A user can perform unauthorized activities due to CVE-2021-20405 by exploiting the improper encoding of output in IBM Security Verify Information Queue 1.0.6 and 1.0.7.
Yes, IBM has provided a fix for CVE-2021-20405. Please refer to the IBM support page for more information.