Weak Cryptographic Algorithms in IBM Cloud Pak System Affects Data Security
CVE-2021-20479

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
9 May 2022

Summary

The IBM Cloud Pak System versions 2.3.0 to 2.3.3.3 Interim Fix 1 have been identified as using weaker than expected cryptographic algorithms. This vulnerability could potentially enable attackers to decrypt sensitive information, posing risks to data confidentiality and integrity. Organizations utilizing these affected versions are encouraged to assess their exposure and implement necessary measures to mitigate potential security risks.

Affected Version(s)

Cloud Pak System 2.3.0

Cloud Pak System 2.3.3.3.Interim.Fix1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.