CVE-2021-20581: IBM Security Verify Privilege information disclosure
Published Oct 5, 2023
·Updated
IBM Security Verify could allow a user to obtain sensitive information due to insufficient session expiration.
Other sources
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324.
— MITRE
Affected Software
4 affected components
IBM Security Verify Privilege On-Premises<=All
IBM Security Verify Privilege On-Premises<11.5
macOS
Microsoft Windows
Remediation
Patch Available
Event History
Oct 5, 2023
CVE Published
via IBM·12:00 AM
Oct 17, 2023
CVE Published
via MITRE·01:17 AM
Data Sourced
via MITRE·01:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-20581.
2
What is the severity of CVE-2021-20581?
The severity of CVE-2021-20581 is medium.
3
What is the affected software?
The affected software is IBM Security Verify Privilege On-Premises version All.
4
How can a user obtain sensitive information due to insufficient session expiration?
A user can obtain sensitive information due to insufficient session expiration by exploiting the vulnerability in IBM Security Verify Privilege On-Premises 11.5.
5
Is there a solution available for CVE-2021-20581?
Yes, IBM has provided a solution for CVE-2021-20581. Please refer to the IBM Support page for more information.