CVE-2021-38862: Weak Encryption
IBM Cloud Pak - Risk Manager/IBM Data Risk Manager (iDNA) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38862.
What is the severity of CVE-2021-38862?
The severity of CVE-2021-38862 is high, with a severity value of 7.5.
What is the affected software for CVE-2021-38862?
The affected software for CVE-2021-38862 is IBM Data Risk Manager (iDNA) 2.0.6.
How can an attacker exploit CVE-2021-38862?
An attacker can exploit CVE-2021-38862 by using weaker than expected cryptographic algorithms to decrypt highly sensitive information.
How can I fix CVE-2021-38862?
You can fix CVE-2021-38862 by applying the patch provided by IBM. Please refer to the IBM support page for instructions on how to obtain and apply the patch.