First published: Thu Jul 29 2021(Updated: )
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.5.0.0 | ||
=1.5.0.1 | ||
=1.6.0.0 | ||
=1.6.1.0 | ||
=1.7.0.0 | ||
=1.7.1.0 | ||
IBM Cloud Pak for Security (CP4S) | <=1.5.0.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.5.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.6.0.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.6.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29696 is a vulnerability in IBM Cloud Pak for Security (CP4S) that could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
IBM Cloud Pak for Security (CP4S) versions 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 are affected by CVE-2021-29696.
CVE-2021-29696 has a severity level of critical.
The reference for CVE-2021-29696 is [https://exchange.xforce.ibmcloud.com/vulnerabilities/200597](https://exchange.xforce.ibmcloud.com/vulnerabilities/200597) and [https://www.ibm.com/support/pages/node/6476940](https://www.ibm.com/support/pages/node/6476940).
To fix CVE-2021-29696, it is recommended to apply the latest security updates provided by IBM for IBM Cloud Pak for Security (CP4S) versions 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0.