CVE-2021-20478: Medium severity IBM Cloud Pak System vulnerability
Published Jul 14, 2021
·Updated
IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497.
Other sources
IBM Cloud Pak System could allow a local user in some situations to view the artifacts of another user in self service console.
— IBM
Affected Software
2 affected components
IBM Cloud Pak System=2.3
IBM Cloud Pak System<=V2.3.3.0 - V2.3.3.3
Remediation
Patch Available
Event History
Jul 14, 2021
CVE Published
via IBM·12:00 AM
Jul 20, 2021
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20478?
The severity of CVE-2021-20478 is medium.
2
How can a local user view the artifacts of another user in IBM Cloud Pak System 2.3?
In some situations, a local user can view the artifacts of another user in self-service console on IBM Cloud Pak System 2.3.
3
Which versions of IBM Cloud Pak System are affected by CVE-2021-20478?
Versions 2.3.3.0 to 2.3.3.3 of IBM Cloud Pak System are affected by CVE-2021-20478.
4
Are there any references available for CVE-2021-20478?
Yes, you can find references for CVE-2021-20478 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/197497) and [Reference 2](https://www.ibm.com/support/pages/node/6473065).