First published: Wed Jul 21 2021(Updated: )
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196341.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM i2 Analyst's Notebook Premium | <=IBM i2 Analyze 4.3.1 | |
IBM i2 Analyst's Notebook Premium | <=IBM i2 Analyze 4.3.0 | |
IBM i2 Analyst's Notebook Premium | <=IBM i2 Analyze 4.3.2 | |
IBM i2 Analyze | =4.3.0 | |
IBM i2 Analyze | =4.3.1 | |
IBM i2 Analyze | =4.3.2 | |
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20430 is a medium severity vulnerability due to the potential for unauthorized access to sensitive information.
To mitigate CVE-2021-20430, update IBM i2 Analyst's Notebook Premium to the latest patched version.
CVE-2021-20430 affects IBM i2 Analyze versions 4.3.0, 4.3.1, and 4.3.2.
CVE-2021-20430 could allow remote attackers to leverage detailed error messages to conduct further attacks.
CVE-2021-20430 is a remote vulnerability that can be exploited through web interactions.