CVE-2021-39082

HIGHCVSS 7.5/10EPSS 0.62%

Last modified

CVE-2021-39082 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.. EPSS estimates a 0.62% chance of exploitation in the next 30 days.

Description

IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.62%

45.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IbmUrbancode Deploy7.0.3.4.1044170
IbmUrbancode Deploy7.0.4.1.1036185
IbmUrbancode Deploy7.0.4.2.1038002
IbmUrbancode Deploy7.0.4.3.1044169
IbmUrbancode Deploy7.0.5.0.1041488
IbmUrbancode Deploy7.0.5.1.1044461
IbmUrbancode Deploy7.0.5.2.1050384
IbmUrbancode Deploy7.1.0.0.1058690
IbmUrbancode Deploy7.1.0.1.1061360
IbmUrbancode Deploy7.1.0.1.ifix01.1062130
IbmUrbancode Deploy7.1.0.2.1063225
IbmUrbancode Deploy7.1.0.3.1069281
IbmUrbancode Deploy7.1.1.0.1073118
IbmUrbancode Deploy7.1.1.1.1074331
IbmUrbancode Deploy7.1.1.2.1090482
IbmUrbancode Deploy7.1.2.0.1100493
IbmUrbancode Deploy7.1.2.1.1104332
IbmUrbancode Deploy7.2.0.0.1109832
IbmUrbancode Deploy7.2.0.1.1114184
IbmUrbancode Deploy7.2.0.2.1116435
IbmUrbancode Deploy7.2.1.0.1123293

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-39082?
IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
How severe is CVE-2021-39082?
CVE-2021-39082 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.62% probability of exploitation in the next 30 days.
How do I fix CVE-2021-39082?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-39082?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST