Lucene search

K
cvelistIbmCVELIST:CVE-2021-20411
HistoryFeb 12, 2021 - 4:35 p.m.

CVE-2021-20411

2021-02-1216:35:31
ibm
www.cve.org
2
ibm
verify info queue
user impersonation
session identifier
security issue

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

20.0%

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191.

CNA Affected

[
  {
    "product": "Security Verify Information Queue",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "1.0.6"
      },
      {
        "status": "affected",
        "version": "1.0.7"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

20.0%

Related for CVELIST:CVE-2021-20411