CVE-2021-20486Sensitive Information Exposure in IBM Cloud PAK FOR Data

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 59.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 26
Latest updateMay 24

Description

IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/cloud_pak_for_data3.0
NVDibm/cloud_pak3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qrvp-5966-c65c: IBM Cloud Pak for Data 32022-05-24
CVEList
CVE-2021-20486: IBM Cloud Pak for Data 32021-05-26