First published: Wed Sep 15 2021(Updated: )
IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 196355.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Bridge | <1.0.7 | |
<=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that could aid in further attacks against the system.
The severity level of IBM Security Verify Bridge vulnerability CVE-2021-20435 is medium with a severity value of 5.5.
A local attacker can exploit the IBM Security Verify Bridge vulnerability CVE-2021-20435 by obtaining sensitive information that could aid in further attacks against the system.
All versions up to and including IBM Security Verify Bridge 1.0.5.0 are affected by the vulnerability CVE-2021-20435. Versions 1.0.6.0 and 1.0.7.0 are not affected.
To fix the IBM Security Verify Bridge vulnerability CVE-2021-20435, update to a version higher than 1.0.7.0.