CVE-2021-20408

Severity
5.5MEDIUM
EPSS
0.0%
top 95.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 24

Description

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7674-88wr-2fm6: IBM Security Verify Information Queue 12022-05-24
CVEList
CVE-2021-20408: IBM Security Verify Information Queue 12021-02-12
CVE-2021-20408 (MEDIUM CVSS 5.5) | IBM Security Verify Information Que | cvebase.io