IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/213651 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/6529200 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
28 Dec 2021, 16:32
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-200 | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/213651 - VDB Entry, Vendor Advisory | |
References | (CONFIRM) https://www.ibm.com/support/pages/node/6529200 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 6.5 |
CPE | cpe:2.3:a:ibm:cloud_pak_for_security:1.7.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_security:1.7.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_security:1.7.1.0:*:*:*:*:*:*:* |
22 Dec 2021, 18:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-12-22 17:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-39013
Mitre link : CVE-2021-39013
CVE.ORG link : CVE-2021-39013
JSON object : View
Products Affected
redhat
- openshift
ibm
- cloud_pak_for_security
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor