First published: Wed Jun 16 2021(Updated: )
IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager | =6.0.2 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-20488.
The severity level of CVE-2021-20488 is high, with a CVSS score of 6.5.
IBM Security Identity Manager version 6.0.2 is affected by CVE-2021-20488.
Yes, an authenticated malicious user can change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured.
You can find more information about CVE-2021-20488 on the IBM X-Force ID page (https://exchange.xforce.ibmcloud.com/vulnerabilities/197789) and the IBM Support page (https://www.ibm.com/support/pages/node/6464081).