CVE-2021-38956: Infoleak
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further attacks against the system. IBM X-Force ID: 212038
Other sources
IBM Security Verify could disclose sensitive version information in HTTP response headers that could aid in further attacks against the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-38956.
What is the severity rating of CVE-2021-38956?
The severity rating of CVE-2021-38956 is medium with a value of 5.3.
How does CVE-2021-38956 affect IBM Security Verify Access?
CVE-2021-38956 may disclose sensitive version information in HTTP response headers, which could aid in further attacks against the system.
Which versions of IBM Security Verify Access are affected by CVE-2021-38956?
IBM Security Verify Access versions 10.0.0, 10.0.1.0, and 10.0.2.0 are affected by CVE-2021-38956.
How can I fix CVE-2021-38956 in IBM Security Verify Access?
IBM has not provided a specific fix for CVE-2021-38956, but recommends applying the latest patches and updates for IBM Security Verify Access to mitigate the vulnerability.