Lucene search

K
cveIbmCVE-2021-38938
HistoryMar 15, 2024 - 4:15 p.m.

CVE-2021-38938

2024-03-1516:15:07
CWE-522
ibm
web.nvd.nist.gov
2451
2
ibm
hats
9.6
9.7
security
credentials
plain text
vulnerability

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.1

Confidence

High

EPSS

0

Percentile

9.0%

IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 210989.

Affected configurations

Nvd
Vulners
Node
ibmhost_access_transformation_servicesRange9.69.6.1.4
OR
ibmhost_access_transformation_servicesRange9.79.7.0.3
VendorProductVersionCPE
ibmhost_access_transformation_services*cpe:2.3:a:ibm:host_access_transformation_services:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Host Access Transformation Services",
    "vendor": "IBM",
    "versions": [
      {
        "lessThanOrEqual": "9.6.1.4",
        "status": "affected",
        "version": "9.6",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "9.7.0.3",
        "status": "affected",
        "version": "9.7",
        "versionType": "semver"
      }
    ]
  }
]

Social References

More

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.1

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2021-38938