CVE-2021-20527: Command Injection
Published Apr 14, 2021
·Updated
IBM Resilient SOAR could allow a privileged user to create create malicious scripts that could be executed as another user.
Other sources
IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759.
Affected Software
7 affected components
IBM Resilient<38.2.41
IBM Resilient>=39.0<39.0.6536
IBM Resilient>=39.1<39.1.46
IBM Resilient>=39.2.17<39.2.21
IBM Resilient>=40.0.6554<40.0.6556
IBM Resilient>=40.1.50<40.1.51
IBM Resilient OnPrem<=IBM Security SOAR
Event History
Apr 14, 2021
CVE Published
via IBM·12:00 AM
Apr 19, 2021
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this IBM Resilient SOAR vulnerability?
The vulnerability ID for this IBM Resilient SOAR vulnerability is CVE-2021-20527.
2
What is the severity level of CVE-2021-20527?
The severity level of CVE-2021-20527 is high with a severity value of 7.2.
3
What is the affected software for CVE-2021-20527?
The affected software for CVE-2021-20527 is IBM Resilient SOAR V38.0.
4
How can a privileged user exploit this vulnerability?
A privileged user can create malicious scripts that could be executed as another user.
5
Are there any references or additional information available for this vulnerability?
Yes, you can find more information about CVE-2021-20527 at the IBM X-Force ID: 198759 and on the IBM support pages.