Sensitive Information Exposure in IBM Security Identity Manager
CVE-2021-29692

3.1LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 May 2021

Summary

IBM Security Identity Manager version 7.0.2 is susceptible to a vulnerability that allows remote attackers to gain access to sensitive information. This issue arises from the improper implementation of HTTP Strict Transport Security, which could enable attackers to execute man-in-the-middle techniques to intercept and exploit data. Organizations utilizing this product should consider immediate steps to implement security measures to mitigate potential risks.

Affected Version(s)

Security Identity Manager 7.0.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.