CVE-2021-39070
Last modified
CVE-2021-39070 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.. EPSS estimates a 1.80% chance of exploitation in the next 30 days.
Description
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Verify Access | 10.0.0 |
| Ibm | Security Verify Access | 10.0.1.0 |
| Ibm | Security Verify Access | 10.0.2.0 |
| Ibm | Security Verify Access Docker | 10.0.0 |
| Ibm | Security Verify Access Docker | 10.0.1.0 |
| Ibm | Security Verify Access Docker | 10.0.2.0 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/215353VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6552318Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/215353VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6552318Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-39070?
How severe is CVE-2021-39070?
How do I fix CVE-2021-39070?
Are you affected by CVE-2021-39070?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
