Lucene search

K
ibmIBM807E68A0BAFDBEC14F1996462B6BF264C3AD6D377F5BC25ABEC0D4ED89DBF70C
HistorySep 17, 2021 - 9:18 p.m.

Security Bulletin: IBM Cloud Pak for Data could allow a local user with special privileges to obtain highly sensitive information

2021-09-1721:18:51
www.ibm.com
9
ibm cloud pak
data
shared credentials
vulnerability
patch
local user
special privileges
sensitive information
audit
security breach

EPSS

0

Percentile

5.1%

Summary

Cloud Pak for Data “shared credentials” are available to authorized users. However, because the credentials are shared, it is difficult to audit access to the connection, to identify the source of data loss, or identify the source of a security breach. You can apply a patch to disable this feature.

Vulnerability Details

CVEID:CVE-2021-38899
**DESCRIPTION:**IBM Cloud Pak for Data could allow a local user with special privileges to obtain highly sensitive information.
CVSS Base score: 4.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/209575 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
CP4D 2.5

Remediation/Fixes

Cloud Pak for Data patches are listed here:

<https://www.ibm.com/support/pages/node/6327429&gt;

<https://www.ibm.com/support/pages/node/6217389&gt;

You may contact IBM support if additional assistance is needed.

Workarounds and Mitigations

None

EPSS

0

Percentile

5.1%

Related for 807E68A0BAFDBEC14F1996462B6BF264C3AD6D377F5BC25ABEC0D4ED89DBF70C