Improper Certificate Validation in IBM Security Verify Bridge
CVE-2021-38864
6.1MEDIUM
Summary
IBM Security Verify Bridge version 1.0.5.0 is susceptible to improper certificate validation, which could potentially allow unauthorized users to access sensitive information. This vulnerability could compromise the confidentiality of data handled by the bridge, making it critical for users to assess their security posture and apply necessary mitigations. More details about the vulnerability can be found on the IBM support page and the IBM X-Force Exchange.
Affected Version(s)
Security Verify Bridge 1.0.5.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved