First published: Thu Jul 29 2021(Updated: )
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198920.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.5.0.0 | ||
=1.5.1.0 | ||
=1.6.0.0 | ||
=1.6.1.0 | ||
=1.7.0.0 | ||
=1.7.1.0 | ||
<=1.5.0.0 | ||
<=1.5.1.0 | ||
<=1.6.0.0 | ||
<=1.6.1.0 | ||
<=1.7.0.0 | ||
<=1.7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20539 is a vulnerability in IBM Cloud Pak for Security (CP4S) that could allow an unauthorized user to access sensitive information through HTTP GET requests.
IBM Cloud Pak for Security versions 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 are affected by CVE-2021-20539.
CVE-2021-20539 has a severity rating of 5.3, which is classified as medium.
CVE-2021-20539 can disclose sensitive information to an unauthorized user, which can be used in further attacks against the system.
To fix CVE-2021-20539, it is recommended to apply the necessary security patches provided by IBM for the affected versions of Cloud Pak for Security.