First published: Wed Sep 15 2021(Updated: )
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208154.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Bridge | <=All | |
IBM Security Verify Bridge | <1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38863 is medium with a CVSS score of 6.5.
CVE-2021-38863 affects IBM Security Verify Bridge version 1.0.5.0 and earlier.
An attacker with local authentication can read user credentials stored in plain clear text.
Yes, upgrading to a version higher than 1.0.7 of IBM Security Verify Bridge resolves the vulnerability.
You can find more information about CVE-2021-38863 in the IBM X-Force ID: 208154 and the IBM support page provided.