First published: Fri Dec 24 2021(Updated: )
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | =10.0.0 | |
IBM Security Verify Access | =10.0.1.0 | |
IBM Security Verify Access | =10.0.2.0 | |
IBM Security Verify Access Docker | =10.0.0 | |
IBM Security Verify Access Docker | =10.0.1.0 | |
IBM Security Verify Access Docker | =10.0.2.0 | |
<=10.0.0, 10.0.1, 10.0.2 | ||
<=10.0.0, 10.0.1, 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39070 is a vulnerability in IBM Security Verify Access with the advanced access control authentication service enabled that could allow an attacker to authenticate as any user on the system.
IBM Security Verify Access versions 10.0.0, 10.0.1, and 10.0.2 are affected by CVE-2021-39070.
CVE-2021-39070 has a severity rating of 9.8 (critical).
CVE-2021-39070 allows an attacker to authenticate as any user on the IBM Security Verify Access appliance.
You can find more information about CVE-2021-39070 on the IBM X-Force Exchange website: https://exchange.xforce.ibmcloud.com/vulnerabilities/215353