CVE-2021-38864: High severity IBM Security Verify Bridge vulnerability
Published Sep 15, 2021
·Updated
IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation. IBM X-Force ID: 208155.
Other sources
IBM Security Verify could allow a user to obtain sensitive information due to improper certificate validation.
— IBM
Affected Software
2 affected components
IBM Security Verify Bridge<1.0.7
IBM Security Verify Bridge<=All
Remediation
Patch Available
Event History
Sep 15, 2021
CVE Published
via IBM·12:00 AM
Sep 23, 2021
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2021-38864.
2
What is the severity rating of CVE-2021-38864?
CVE-2021-38864 has a severity rating of 7.5 (High).
3
How does CVE-2021-38864 allow a user to obtain sensitive information?
CVE-2021-38864 allows a user to obtain sensitive information due to improper certificate validation.
4
Which IBM product is affected by CVE-2021-38864?
The IBM product affected by CVE-2021-38864 is IBM Security Verify Bridge.
5
How can I fix the vulnerability in IBM Security Verify Bridge?
To fix the vulnerability in IBM Security Verify Bridge, update to version 1.0.7 or higher.