A security vulnerability in Vault affects Bastion Service of IBM Cloud Pak for Multicloud Managemen 2.2.0 and previous version
CVEID:CVE-2020-16250
**DESCRIPTION:**HashiCorp Vault and Vault Enterprise could allow a remote attacker to bypass security restrictions, caused by a flaw when configured with the AWS IAM auth method. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass authentication.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/187422 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVEID:CVE-2020-16251
**DESCRIPTION:**HashiCorp Vault and Vault Enterprise could allow a remote attacker to bypass security restrictions, caused by a flaw when configured with the GCP GCE auth method. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass authentication.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/187421 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Cloud Pak for Multicloud Management Core | All |
Upgrade to IBM Cloud Pak for Multicloud Management 2.x.x to 2.2.1 or later by following the instructions in https://www.ibm.com/support/knowledgecenter/en/SSFC4F_2.2.0/install/upgrade.html
None