IBM Security Verify Access privilege escalation | CVE-2021-39070
NAME
IBM Security Verify Access privilege escalation
- Platforms Affected:
IBM Security Verify Access Appliance 10.0.0.0
IBM Security Verify Access Docker 10.0.0.0
IBM Security Verify Access Docker 10.0.1.0
IBM Security Verify Access Docker 10.0.2.0
IBM Security Verify Access Appliance 10.0.1.0
IBM Security Verify Access Appliance 10.0.2.0 - Risk Level:
9.8 - Exploitability:
Unproven - Consequences:
Gain Privileges
DESCRIPTION
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Refer to IBM Security Bulletin 6552318 for patch, upgrade or suggested workaround information. See References.
- Reference Link:
https://www.ibm.com/support/pages/node/6552318 - Reference Link:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39070
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.