CVE-2021-20567Missing Encryption of Sensitive Data in IBM Resilient Soar

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 97.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateMay 24

Description

IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r579-4369-crhp: IBM Resilient SOAR V382022-05-24
CVEList
CVE-2021-20567: IBM Resilient SOAR V382021-06-16
CVE-2021-20567 — Missing Encryption of Sensitive Data | cvebase