CVE-2021-39089: IBM Cloud Pak for Security information disclosure
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 216387.
Other sources
IBM Cloud Pak for Security (CP4S) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-39089?
CVE-2021-39089 is a vulnerability in IBM Cloud Pak for Security (CP4S) that could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request.
How severe is CVE-2021-39089?
CVE-2021-39089 has a severity value of 6.5 (Medium).
Which software versions are affected by CVE-2021-39089?
IBM Cloud Pak for Security (CP4S) versions 1.10.0.0 through 1.10.6.0 are affected by CVE-2021-39089.
How can an authenticated user exploit CVE-2021-39089?
An authenticated user can exploit CVE-2021-39089 by sending a specially crafted HTTP request to obtain sensitive information.
Where can I find more information about CVE-2021-39089?
You can find more information about CVE-2021-39089 at the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/216387) [link2](https://www.ibm.com/support/pages/node/6856405).