CVE-2021-38859: IBM Security Verify Privilege information disclosure
IBM Secret Server Account Lifecycle Manager could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system.
Other sources
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID: 207899.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for IBM Security Verify Privilege On-Premises?
The vulnerability ID for IBM Security Verify Privilege On-Premises is CVE-2021-38859.
What is the severity of CVE-2021-38859?
The severity of CVE-2021-38859 is medium with a CVSS score of 4.3.
How can a user exploit CVE-2021-38859?
A user can exploit CVE-2021-38859 by sending a specially crafted HTTP request to obtain version number information.
What is the affected software for CVE-2021-38859?
The affected software for CVE-2021-38859 is IBM Security Verify Privilege On-Premises version All.
Where can I find more information about CVE-2021-38859?
You can find more information about CVE-2021-38859 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/207899) [Reference 2](https://www.ibm.com/support/pages/node/7047202)