CVE-2021-40087: Low severity PrimeKey EJBCA vulnerability
An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40087?
CVE-2021-40087 has been classified as a high severity vulnerability due to the exposure of sensitive information in cleartext.
How do I fix CVE-2021-40087?
To mitigate CVE-2021-40087, upgrade EJBCA to version 7.6.0 or later where the issue has been resolved.
What systems are affected by CVE-2021-40087?
CVE-2021-40087 affects PrimeKey EJBCA versions prior to 7.6.0 that utilize enrollment secrets for protocol configurations.
What types of data are exposed in CVE-2021-40087?
CVE-2021-40087 exposes modifications to enrollment secrets in cleartext within the audit logs.
Who can access the information logged in CVE-2021-40087?
Only administrators can view the audit logs affected by CVE-2021-40087, which contain the cleartext sensitive information.