CVE-2021-20434: Medium severity ibm security verify bridge vulnerability
Published Sep 15, 2021
·Updated
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346.
Other sources
IBM Security Verify Bridge stores user credentials in plain clear text which can be read by a local user.
— IBM
Affected Software
2 affected components
IBM Security Verify Bridge<1.0.7
IBM Security Verify Bridge<=All
Remediation
Patch Available
Patch Available
Event History
Sep 15, 2021
CVE Published
via IBM·12:00 AM
Sep 23, 2021
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-20434.
2
What is the severity of CVE-2021-20434?
CVE-2021-20434 has a severity value of 4.4, which is considered medium.
3
What is the affected software?
The affected software is IBM Security Verify Bridge versions up to and including 1.0.7.
4
How does CVE-2021-20434 affect the software?
CVE-2021-20434 allows a local user to read user credentials stored in plain text in IBM Security Verify Bridge.
5
How can I fix CVE-2021-20434?
To fix CVE-2021-20434, update your IBM Security Verify Bridge installation to version 1.0.7 or newer.