Lucene search

K
ibmIBM12A7B12FFEE0F2FE39355354CFD380B6B56E5F3D700D32F1E2FF73515D5945EC
HistoryMar 09, 2021 - 6:36 p.m.

Security Bulletin: IBM Security Verify Bridge uses relatively weak cryptographic algorithms in two of its functions (CVE-2021-20441)

2021-03-0918:36:01
www.ibm.com
7

0.001 Low

EPSS

Percentile

43.8%

Summary

In two instances, IBM Security Verify Bridge (ISVB) uses a relatively weak cryptographic algorithm. (1) If no transport layer security (TLS) preference is specified, ISVB defaults to TLS 1.0 which has known vulnerabilities. (2) When generating a random number during LDAP bind authentication, ISVB chooses an older, less secure randomizer. As of v1.0.5, ISVB is now defaulting to TLS 1.2 and is using a cryptographically strong random number generator.

Vulnerability Details

CVEID:CVE-2021-20441
**DESCRIPTION:**IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/196617 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Verify Bridge All

Remediation/Fixes

Log in to IBM X-Force Exchange / App Exchange and download and install IBM Security Verify Bridge v1.0.5 (or later) at <https://exchange.xforce.ibmcloud.com/hub/extension/1c7235901d5d37bf06665ce56d5ab426&gt;

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm security verify bridgeeqany

0.001 Low

EPSS

Percentile

43.8%

Related for 12A7B12FFEE0F2FE39355354CFD380B6B56E5F3D700D32F1E2FF73515D5945EC