First published: Mon Jul 12 2021(Updated: )
IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Applications | <4.3.1 | |
<=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-20424 is considered to be moderate as it allows remote attackers to obtain sensitive information.
To fix CVE-2021-20424, ensure that error messages displayed in the browser do not reveal sensitive information.
CVE-2021-20424 affects IBM Cloud Pak for Applications versions up to 4.3.1.
The information obtained from CVE-2021-20424 could be used by attackers for further targeted attacks on the system.
Using IBM Cloud Pak for Applications while CVE-2021-20424 is unpatched carries a risk of information disclosure that can lead to increased vulnerability.