First published: Wed Sep 08 2021(Updated: )
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | =1.7.0.0 | |
IBM Cloud Pak for Security | =1.7.1.0 | |
IBM Cloud Pak for Security | =1.7.2.0 | |
Redhat Openshift | ||
<=1.7.2.0 | ||
<=1.7.1.0 | ||
<=1.7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20578 is a vulnerability in IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 that allows an attacker to perform unauthorized actions due to improper or missing authentication controls.
An attacker can exploit CVE-2021-20578 by taking advantage of the improper or missing authentication controls in IBM Cloud Pak for Security (CP4S) to perform unauthorized actions.
CVE-2021-20578 has a severity rating of 9.8, which is considered critical.
CVE-2021-20578 affects IBM Cloud Pak for Security (CP4S) versions 1.7.0.0, 1.7.1.0, and 1.7.2.0.
To fix CVE-2021-20578, update IBM Cloud Pak for Security (CP4S) to a version that includes proper authentication controls.