Severity
5.3MEDIUM
EPSS
0.1%
top 68.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 24

Description

IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q7mh-g4jf-h3rv: IBM Security Verify Information Queue 12022-05-24
CVEList
CVE-2021-20410: IBM Security Verify Information Queue 12021-02-12
CVE-2021-20410 (MEDIUM CVSS 5.3) | IBM Security Verify Information Que | cvebase.io