Sensitive Information Disclosure in IBM Cloud Pak for Applications
CVE-2021-20422

7.5HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
13 July 2021

Summary

The vulnerability in IBM Cloud Pak for Applications 4.3 allows unauthorized access to sensitive data residing in memory. A malicious attacker could exploit this flaw to retrieve confidential information, which poses significant risks to organizations relying on the application for their operations. Protecting sensitive data is crucial, and users should assess their exposure to this risk.

Affected Version(s)

Cloud Pak for Applications 4.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.