CVE-2021-38915: Medium severity ibm data risk manager vulnerability
Published Oct 6, 2021
·Updated
IBM Cloud Pak - Risk Manager stores user credentials in plain clear text which can be read by an authenticated user.
Other sources
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.
Affected Software
2 affected componentsFixes available
IBM Data Risk Manager=2.0.6
IBM DRM<=2.0.6
Event History
Oct 6, 2021
CVE Published
via IBM·12:00 AM
Oct 12, 2021
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38915.
2
What is the title of the vulnerability?
The title of the vulnerability is 'IBM Cloud Pak - Risk Manager stores user credentials in plain clear text which can be read by an authenticated user.'
3
What is the severity of CVE-2021-38915?
The severity of CVE-2021-38915 is medium with a severity value of 6.5.
4
How can an authenticated user read the plain clear text user credentials in IBM Data Risk Manager 2.0.6?
As an authenticated user, one can read the plain clear text user credentials in IBM Data Risk Manager 2.0.6.
5
How can I fix CVE-2021-38915?
To fix CVE-2021-38915, apply the patch provided by IBM for IBM Data Risk Manager 2.0.6.