Lucene search

K
ibmIBM76D5EAC571668C27B7C311B116850678A38D6DA186100DE3BEE962AB1F8949E2
HistoryJun 25, 2021 - 5:12 a.m.

Security Bulletin: Multiple Vulnerabilities Have Been Identified In IBM Security Verify Privilege Vault

2021-06-2505:12:01
www.ibm.com
12
ibm security verify privilege vault
vulnerabilities
link injection
cross-site scripting
sensitive information disclosure
cve-2021-29676
cve-2021-20583
cve-2021-29677
upgrade

EPSS

0.001

Percentile

28.9%

Summary

Multiple vulnerabilities identified in IBM Security Verify Privilege Vault previously known as IBM Security Secret Server has been addressed in the release 10.9.66

Vulnerability Details

CVEID:CVE-2021-29676
**DESCRIPTION:**IBM Security Verify is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking
CVSS Base score: 4.6
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199575 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)

CVEID:CVE-2021-20583
**DESCRIPTION:**IBM Security Verify could disclose sensitive information through an HTTP GET request by a privileged user due to improper input validation…
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199396 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N)

CVEID:CVE-2021-29677
**DESCRIPTION:**IBM Security Verify is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199578 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

All releases prior to 10.9.66

Remediation/Fixes

Upgrade to the latest release available here.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

28.9%

Related for 76D5EAC571668C27B7C311B116850678A38D6DA186100DE3BEE962AB1F8949E2