CVE-2021-38863: Medium severity IBM Security Verify Bridge vulnerability
Published Sep 15, 2021
·Updated
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208154.
Other sources
IBM Security Verify stores user credentials in plain clear text which can be read by a locally authenticated user.
Affected Software
2 affected components
IBM Security Verify Bridge<1.0.7
IBM Security Verify Bridge<=All
Remediation
Patch Available
Event History
Sep 15, 2021
CVE Published
via IBM·12:00 AM
Sep 23, 2021
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38863?
The severity of CVE-2021-38863 is medium with a CVSS score of 6.5.
2
What does CVE-2021-38863 affect?
CVE-2021-38863 affects IBM Security Verify Bridge version 1.0.5.0 and earlier.
3
How can an attacker exploit CVE-2021-38863?
An attacker with local authentication can read user credentials stored in plain clear text.
4
Is there a fix for CVE-2021-38863?
Yes, upgrading to a version higher than 1.0.7 of IBM Security Verify Bridge resolves the vulnerability.
5
Where can I find more information about CVE-2021-38863?
You can find more information about CVE-2021-38863 in the IBM X-Force ID: 208154 and the IBM support page provided.