CVE-2021-38891: Weak Encryption
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.
Other sources
IBM Sterling Connect:Direct Web Services uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38891?
CVE-2021-38891 is considered to have a high severity due to its potential to allow attackers to decrypt sensitive information.
How do I fix CVE-2021-38891?
To fix CVE-2021-38891, upgrade IBM Sterling Connect:Direct Web Services to a version that uses stronger cryptographic algorithms.
What versions of IBM Sterling Connect:Direct are affected by CVE-2021-38891?
IBM Sterling Connect:Direct Web Services versions 1.0 and 6.0 are affected by CVE-2021-38891.
Can CVE-2021-38891 impact compliance with data protection laws?
Yes, CVE-2021-38891 could impact compliance with data protection laws due to its potential to expose sensitive information.
Is IBM Sterling Connect:Direct Web Services the only affected software for CVE-2021-38891?
Yes, CVE-2021-38891 specifically affects IBM Sterling Connect:Direct Web Services.