First published: Tue Sep 14 2021(Updated: )
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | <=10.0.0 | |
IBM Security Verify Access | =10.0.0 | |
IBM Security Verify Access | =10.0.1.0 | |
IBM Security Verify Access | =10.0.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38957 is high.
CVE-2021-38957 affects IBM Security Verify Access versions 10.0.0, 10.0.1.0, and 10.0.2.0.
The risk of disclosing sensitive information due to hazardous input validation during QR code generation in IBM Security Verify is high.
To fix the vulnerability in IBM Security Verify, upgrade to a version that is not affected, as recommended by IBM.
You can find more information about CVE-2021-38957 on the IBM X-Force Exchange website and the IBM Support page.