CVE-2021-38921: High severity ibm security verify access oidc provider vulnerability
IBM Security Access Manager Appliance uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-38921?
CVE-2021-38921 is a vulnerability in IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 that uses weaker than expected cryptographic algorithms, allowing an attacker to decrypt highly sensitive information.
What is the severity of CVE-2021-38921?
The severity of CVE-2021-38921 is high with a CVSS score of 7.5.
How does CVE-2021-38921 affect IBM Security Verify Access?
CVE-2021-38921 affects IBM Security Verify Access versions 10.0.0, 10.0.1.0, and 10.0.2.0.
How can an attacker exploit CVE-2021-38921?
An attacker can exploit CVE-2021-38921 by using weaker cryptographic algorithms to decrypt highly sensitive information.
Is there a fix available for CVE-2021-38921?
Yes, IBM has provided a fix for CVE-2021-38921. Please refer to the official IBM Security Access Manager documentation for details on how to apply the fix.