First published: Thu Feb 04 2021(Updated: )
IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196184.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Information Queue | =1.0.6 | |
IBM Security Verify Information Queue | =1.0.7 | |
Linux Linux kernel | ||
IBM Security Verify Information Queue | <=1.0.6, 1.0.7 | |
All of | ||
Linux Linux kernel | ||
Any of | ||
IBM Security Verify Information Queue | =1.0.6 | |
IBM Security Verify Information Queue | =1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20406.
The severity of CVE-2021-20406 is medium.
The affected software for CVE-2021-20406 is IBM Security Verify Information Queue versions 1.0.6 and 1.0.7.
CVE-2021-20406 could allow an attacker to decrypt highly sensitive information.
To mitigate CVE-2021-20406, update to a version of IBM Security Verify Information Queue that uses stronger cryptographic algorithms.