First published: Thu Feb 04 2021(Updated: )
IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Information Queue | <=1.0.6, 1.0.7 | |
IBM Security Verify Information Queue | =1.0.6 | |
IBM Security Verify Information Queue | =1.0.7 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20410.
The severity of CVE-2021-20410 is medium with a severity value of 5.3.
The affected software for CVE-2021-20410 is IBM Security Verify Information Queue versions 1.0.6 and 1.0.7.
An authenticated user can exploit CVE-2021-20410 by using man-in-the-middle techniques to read user credentials sent in plain clear text.
Yes, IBM has provided a fix for CVE-2021-20410. Please refer to the IBM support page for more information.