First published: Wed Sep 15 2021(Updated: )
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Bridge | <1.0.7 | |
IBM Security Verify Bridge | <=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-20434.
CVE-2021-20434 has a severity value of 4.4, which is considered medium.
The affected software is IBM Security Verify Bridge versions up to and including 1.0.7.
CVE-2021-20434 allows a local user to read user credentials stored in plain text in IBM Security Verify Bridge.
To fix CVE-2021-20434, update your IBM Security Verify Bridge installation to version 1.0.7 or newer.