CVE-2021-20569: Input Validation
Published Jul 29, 2021
·Updated
IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. IBM X-Force ID: 199243.
Other sources
IBM Security Verify Privilege could allow an attacker to enumerate usernames due to improper input validation.
— IBM
Affected Software
2 affected components
IBM Security Secret Server<11.0
Microsoft Windows
Event History
Jul 29, 2021
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Sep 14, 2021
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-20569.
2
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Security Verify Privilege could allow an attacker to enumerate usernames due to improper input validation.'
3
What is the affected software?
The affected software is IBM Security Secret Server up to version 11.0.
4
What is the severity of CVE-2021-20569?
The severity of CVE-2021-20569 is medium with a CVSS score of 5.3.
5
How can this vulnerability be fixed?
Update IBM Security Secret Server to a version that includes a fix for CVE-2021-20569.