IBM Cloud Pak for Security Vulnerability Could Lead to Sensitive Information Theft
CVE-2021-39090
What is CVE-2021-39090?
A vulnerability exists in IBM Cloud Pak for Security which allows a remote attacker to potentially exploit the improper configuration of HTTP Strict Transport Security (HSTS). This misconfiguration can lead to sensitive information exposure through man-in-the-middle attacks, allowing unauthorized individuals to intercept communications. Organizations utilizing affected versions of IBM Cloud Pak for Security are advised to review their HSTS settings and apply necessary patches to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cloud Pak for Security 1.10.0.0 <= 1.10.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved