CVE-2021-38911: Medium severity ibm security risk manager on cp4s vulnerability
IBM Cloud Pak - Risk Manager stores user credentials in plain clear text which can be read by a an authenticatedl privileged user.
Other sources
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38911?
CVE-2021-38911 is considered a high severity vulnerability due to the exposure of user credentials in plain text.
How do I fix CVE-2021-38911?
To fix CVE-2021-38911, it is recommended to upgrade IBM Security Risk Manager on CP4S to version 1.7.2.1 or higher where the issue is resolved.
Who is affected by CVE-2021-38911?
CVE-2021-38911 affects users of IBM Security Risk Manager on CP4S versions up to and including 1.7.2.0.
What type of data is exposed in CVE-2021-38911?
CVE-2021-38911 exposes sensitive user credentials stored in plain clear text.
Can an unprivileged user exploit CVE-2021-38911?
No, CVE-2021-38911 requires an authenticated privileged user to read the exposed user credentials.