Lucene search

K
ibmIBM157670D069677DAAB799738D5DA0D102EC51B447138B0FE39A2A0CE9A6ECBEE3
HistoryMar 11, 2021 - 5:50 a.m.

Security Bulletin: A security vulnerability in Vault affects Bastion Service of IBM Cloud Pak for Multicloud Management

2021-03-1105:50:03
www.ibm.com
11
ibm cloud pak
vault
security vulnerability
vulnerability bypass
aws iam
gcp gce
remote attack
authentication bypass
cvss score
upgrade

EPSS

0.004

Percentile

72.2%

Summary

A security vulnerability in Vault affects Bastion Service of IBM Cloud Pak for Multicloud Managemen 2.2.0 and previous version

Vulnerability Details

CVEID:CVE-2020-16250
**DESCRIPTION:**HashiCorp Vault and Vault Enterprise could allow a remote attacker to bypass security restrictions, caused by a flaw when configured with the AWS IAM auth method. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass authentication.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/187422 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2020-16251
**DESCRIPTION:**HashiCorp Vault and Vault Enterprise could allow a remote attacker to bypass security restrictions, caused by a flaw when configured with the GCP GCE auth method. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass authentication.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/187421 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Core All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.x.x to 2.2.1 or later by following the instructions in https://www.ibm.com/support/knowledgecenter/en/SSFC4F_2.2.0/install/upgrade.html

Workarounds and Mitigations

None

EPSS

0.004

Percentile

72.2%

Related for 157670D069677DAAB799738D5DA0D102EC51B447138B0FE39A2A0CE9A6ECBEE3