First published: Fri May 21 2021(Updated: )
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196315.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium | =11.2 | |
Linux Linux kernel | ||
<=10.5 | ||
<=10.6 | ||
<=11.0 | ||
<=11.1 | ||
<=11.2 | ||
<=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20428 is a vulnerability in IBM Security Guardium 11.2 that could allow a remote attacker to obtain sensitive information.
CVE-2021-20428 exploits a weakness in IBM Security Guardium 11.2 that allows a detailed technical error message to be returned in the browser, which can then be used by an attacker to gather sensitive information for further attacks.
CVE-2021-20428 has a severity level of 5.3 (medium).
No, other versions of IBM Security Guardium (10.5, 10.6, 11.0, 11.1, 11.3) may also be affected.
To protect your system from CVE-2021-20428, it is recommended to apply the necessary security updates provided by IBM Security Guardium.