Improper Certificate Validation in IBM Security Verify Bridge
CVE-2021-38864

6.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
23 September 2021

Summary

IBM Security Verify Bridge version 1.0.5.0 is susceptible to improper certificate validation, which could potentially allow unauthorized users to access sensitive information. This vulnerability could compromise the confidentiality of data handled by the bridge, making it critical for users to assess their security posture and apply necessary mitigations. More details about the vulnerability can be found on the IBM support page and the IBM X-Force Exchange.

Affected Version(s)

Security Verify Bridge 1.0.5.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.