First published: Thu Jul 29 2021(Updated: )
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 203091.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Partner Engagement Manager | =2.0 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-29781 is critical with a CVSS score of 9.8.
CVE-2021-29781 allows a remote attacker to execute arbitrary code on the system running IBM Partner Engagement Manager 2.0.
CVE-2021-29781 is caused by an unsafe deserialization flaw in IBM Partner Engagement Manager 2.0.
Yes, CVE-2021-29781 can be exploited remotely by sending specially-crafted data.
IBM has provided a fix for the vulnerability. Please refer to the IBM support page for more details.