Lucene search

K
ibmIBMFF34999DCDB38A3D831D72617790B03F8FCC54B7E3726D66555E8A001B54E076
HistoryAug 29, 2022 - 9:32 p.m.

Security Bulletin: A security vulnerability has been fixed in IBM Security Identity Manager (CVE-2021-29864)

2022-08-2921:32:25
www.ibm.com
25
ibm security identity manager
cve-2021-29864
phishing attacks
open redirect

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

36.3%

Summary

A security vulnerability has been fixed in IBM Security Identity Manager.

Vulnerability Details

CVEID:CVE-2021-29864
**DESCRIPTION:**IBM Security Identity Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
CVSS Base score: 6.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/206089 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
ISIM 6.0.0
ISIM 6.0.2

Remediation/Fixes

Affected Product / Version Fix availability
IBM Security Identity Manager 6.0.0 6.0.0-ISS-SIM-FP0027
IBM Security Identity Manager 6.0.2 6.0.2-ISS-SIM-FP0005

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmsecurity_identity_managerMatch6.0
OR
ibmsecurity_identity_managerMatch6.0.2

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

36.3%

Related for FF34999DCDB38A3D831D72617790B03F8FCC54B7E3726D66555E8A001B54E076