CVE-2021-20540
Summary
| CVE | CVE-2021-20540 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-02 17:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198923. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Cloud Pak For Security | 1.5.0.0 | All | All | All |
| Application | Ibm | Cloud Pak For Security | 1.5.1.0 | All | All | All |
| Application | Ibm | Cloud Pak For Security | 1.6.0.0 | All | All | All |
| Application | Ibm | Cloud Pak For Security | 1.6.1.0 | All | All | All |
| Application | Ibm | Cloud Pak For Security | 1.7.0.0 | All | All | All |
| Application | Ibm | Cloud Pak For Security | 1.7.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Security Bulletin: Cloud Pak for Security has several security vulnerabilities addressed in the latest version | CONFIRM | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.