Lucene search

K
ibmIBM2519C018961616E9BA166B96F74E5084D21FD2846C629E82F01ACC30868BE906
HistoryMar 11, 2021 - 5:53 a.m.

Security Bulletin: A security vulnerability in Vault affects Bastion Service of IBM Cloud Pak for Multicloud Management

2021-03-1105:53:03
www.ibm.com
7

0.001 Low

EPSS

Percentile

28.4%

Summary

A security vulnerability in Vault affects Bastion Service of IBM Cloud Pak for Multicloud Managemen 2.2.0 and previous version

Vulnerability Details

CVEID:CVE-2020-25816
**DESCRIPTION:**HashiCorp Vault and Vault Enterprise could allow a remote attacker to bypass security restrictions, caused by incorrect access control. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass access restrictions.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/189353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Core All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.x.x to 2.2.1 or later by following the instructions in https://www.ibm.com/support/knowledgecenter/en/SSFC4F_2.2.0/install/upgrade.html.

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

28.4%

Related for 2519C018961616E9BA166B96F74E5084D21FD2846C629E82F01ACC30868BE906