First published: Thu Jul 29 2021(Updated: )
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198923.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.5.0.0 | ||
=1.5.1.0 | ||
=1.6.0.0 | ||
=1.6.1.0 | ||
=1.7.0.0 | ||
=1.7.1.0 | ||
<=1.5.0.0 | ||
<=1.5.1.0 | ||
<=1.6.0.0 | ||
<=1.6.1.0 | ||
<=1.7.0.0 | ||
<=1.7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20540 is a vulnerability in IBM Cloud Pak for Security (CP4S) that could disclose sensitive information to an unauthorized user through HTTP GET requests.
Versions 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 of IBM Cloud Pak for Security (CP4S) are affected by CVE-2021-20540.
CVE-2021-20540 has a severity rating of 5.3 (medium).
An unauthorized user can exploit CVE-2021-20540 by sending HTTP GET requests to gain access to sensitive information.
Yes, you can find more information about CVE-2021-20540 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/198923), [Reference 2](https://www.ibm.com/support/pages/node/6476940).