First published: Fri Nov 26 2021(Updated: )
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197498.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak System | >=2.3.0.0<2.3.3.4 | |
<=V2.3.0 - V2.3.3.3 Interim Fix 1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-20479.
The severity of CVE-2021-20479 is high (7.5).
The affected software for CVE-2021-20479 is IBM Cloud Pak System versions 2.3.0 through 2.3.3.3 Interim Fix 1.
The impact of CVE-2021-20479 is that an attacker could decrypt highly sensitive information.
Yes, IBM has released a fix for CVE-2021-20479. Please refer to the IBM support page for more information.