Information Disclosure Vulnerability in IBM Security SOAR
CVE-2021-29785
5.9MEDIUM
What is CVE-2021-29785?
The vulnerability in IBM Security SOAR V42 and V43 results from improper enforcement of HTTP Strict Transport Security, which allows a remote attacker to exploit this weakness. By employing man-in-the-middle techniques, the attacker could capture sensitive information communicated between users and the application. Proper configuration and patching are critical to mitigating the risk posed by this vulnerability.
Affected Version(s)
Security SOAR 42
Security SOAR 43