First published: Wed Jul 21 2021(Updated: )
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 202680.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM i2 Analyze | <=IBM i2 Analyze 4.3.1 | |
IBM i2 Analyze | <=IBM i2 Analyze 4.3.0 | |
IBM i2 Analyze | <=IBM i2 Analyze 4.3.2 | |
IBM i2 Analyze | =4.3.0 | |
IBM i2 Analyze | =4.3.1 | |
IBM i2 Analyze | =4.3.2 | |
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29766 has a medium severity rating as it allows remote attackers to obtain sensitive information through detailed error messages.
To fix CVE-2021-29766, upgrade to a patched version of IBM i2 Analyze beyond 4.3.2.
CVE-2021-29766 affects IBM i2 Analyze versions 4.3.0, 4.3.1, and 4.3.2.
CVE-2021-29766 is classified as an information disclosure vulnerability.
Yes, the information disclosed in CVE-2021-29766 can be utilized in subsequent attacks against the system.