First published: Wed Jan 18 2023(Updated: )
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 216387.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | >=1.10.0.0<=1.10.6.0 | |
Linux Linux kernel | ||
<=1.10.0.0 - 1.10.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39089 is a vulnerability in IBM Cloud Pak for Security (CP4S) that could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request.
CVE-2021-39089 has a severity value of 6.5 (Medium).
IBM Cloud Pak for Security (CP4S) versions 1.10.0.0 through 1.10.6.0 are affected by CVE-2021-39089.
An authenticated user can exploit CVE-2021-39089 by sending a specially crafted HTTP request to obtain sensitive information.
You can find more information about CVE-2021-39089 at the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/216387) [link2](https://www.ibm.com/support/pages/node/6856405).