Local Certificate Validation Flaw in IBM Security Verify Bridge
CVE-2021-20435

2.5LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
23 September 2021

Summary

IBM Security Verify Bridge version 1.0.5.0 is susceptible to a vulnerability where it fails to properly validate certificates. This security weakness could enable a local attacker to exploit the system by accessing sensitive information that could facilitate further attacks. To mitigate potential risks, affected users should promptly apply updates and patches provided by IBM to secure their installations.

Affected Version(s)

Security Verify Bridge 1.0.5.0

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.