First published: Mon Jun 28 2021(Updated: )
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager Adapter | =6.0.0.0 | |
IBM Security Identity Manager Adapter | =7.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20574 has a medium severity rating due to its potential for account takeover via LDAP injection.
To fix CVE-2021-20574, update IBM Security Identity Manager Adapters to the latest patched version provided by IBM.
CVE-2021-20574 affects users of IBM Security Identity Manager Adapters versions 6.0.0.0 and 7.0.0.0.
CVE-2021-20574 allows a remote authenticated attacker to conduct an LDAP injection attack.
By exploiting CVE-2021-20574, an attacker could potentially take over other user accounts.