First published: Tue Sep 14 2021(Updated: )
IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =10.6 | |
IBM InfoSphere Guardium z/OS | =11.3 | |
Linux Kernel | ||
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29773 has a medium severity rating due to its potential impact on sensitive information exposure and user detail modifications.
To fix CVE-2021-29773, upgrade IBM Security Guardium to version 10.6 or 11.3 or apply the latest patches provided by IBM.
CVE-2021-29773 could allow remote authenticated attackers to exploit an insecure direct object reference to obtain sensitive information.
CVE-2021-29773 affects IBM Security Guardium versions 10.6 and 11.3.
CVE-2021-29773 was identified by IBM X-Force, with the associated ID being 202865.