Hard-Coded Credential Vulnerability in IBM Security Verify Information Queue
CVE-2021-20412

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
12 February 2021

Summary

IBM Security Verify Information Queue versions 1.0.6 and 1.0.7 are affected by a vulnerability due to hard-coded credentials stored within the software. These credentials, which include passwords or cryptographic keys, are utilized for various functions, such as inbound authentication and outbound communications with external components. This exposure poses significant security risks, as it allows unauthorized access to sensitive data and potentially enables further exploitation of the system. Users of the affected versions are strongly advised to apply the necessary updates and review their security configurations to mitigate these risks. For additional information and guidance, consult IBM's security resources.

Affected Version(s)

Security Verify Information Queue 1.0.6

Security Verify Information Queue 1.0.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.