First published: Tue Sep 21 2021(Updated: )
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | =1.1.3.10 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=1.1.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-29904 is medium with a CVSS score of 6.2.
A local user can read user credentials in plain clear text in IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI.
IBM Jazz for Service Management version 1.1.3.10 is affected by CVE-2021-29904.
No, IBM AIX is not vulnerable to CVE-2021-29904.
You can find more information about CVE-2021-29904 on the IBM X-Force Exchange website and the IBM support pages.