CVE-2021-29749

Severity
5.4MEDIUM
EPSS
0.2%
top 52.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages4 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6q52-mr9g-rhrv: IBM Secure External Authentication Server 62022-05-24
CVEList
CVE-2021-29749: IBM Secure External Authentication Server 62021-07-15
CVE-2021-29749 (MEDIUM CVSS 5.4) | IBM Secure External Authentication | cvebase.io