CVE-2021-39090: IBM Cloud Pak for Security information disclosure
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 216388.
Other sources
IBM Cloud Pak for Security (CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39090?
CVE-2021-39090 is classified as a medium severity vulnerability.
How do I fix CVE-2021-39090?
To fix CVE-2021-39090, upgrade IBM Cloud Pak for Security to version 1.10.7.0 or later.
What type of information could an attacker obtain from CVE-2021-39090?
An attacker could potentially obtain sensitive information due to the improper implementation of HTTP Strict Transport Security.
What versions of IBM Cloud Pak for Security are affected by CVE-2021-39090?
Versions 1.10.0.0 through 1.10.6.0 of IBM Cloud Pak for Security are affected by CVE-2021-39090.
Is there a public report available for CVE-2021-39090?
Yes, a public report detailing CVE-2021-39090 is available on IBM's support page.