Vulnerability Name: | CVE-2021-20432 (CCN-196344) | ||||||||||||
Assigned: | 2020-12-17 | ||||||||||||
Published: | 2021-04-23 | ||||||||||||
Updated: | 2021-04-30 | ||||||||||||
Summary: | IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 196344. | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-20432 Source: XF Type: UNKNOWN ibm-spectrum-cve202120432-info-disc(196344) Source: XF Type: VDB Entry, Vendor Advisory ibm-spectrum-cve202120432-info-disc (196344) Source: CCN Type: IBM Security Bulletin 6445733 (Spectrum Protect Plus) Cross-Origin Resource Sharing (CORS) vulnerability in IBM Spectrum Protect Plus (CVE-2021-20432) Source: CONFIRM Type: Vendor Advisory https://www.ibm.com/support/pages/node/6445733 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |