CVE-2021-20431

Severity
6.5MEDIUM
EPSS
0.2%
top 62.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 24

Description

IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 196342.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/i2_analyst's_notebook_premium9.2.0, 9.2.1, 9.2.2+2
NVDibm/i2_analysts_notebook9.2.0, 9.2.1, 9.2.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7pr3-55xw-4rxx: IBM i2 Analyst's Notebook Premium 92022-05-24
CVEList
CVE-2021-20431: IBM i2 Analyst's Notebook Premium 92021-07-26
CVE-2021-20431 (MEDIUM CVSS 6.5) | IBM i2 Analyst's Notebook Premium 9 | cvebase.io