PublicCVE

CVE-2021-20564

MEDIUM5.9JSON exportCreate alert

Description

IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 199235.

CVSS breakdown

CVSS 3.0
Privileges Required
None
User Interaction
None
Integrity
None
Attack Complexity
High
Attack Vector
Network
Confidentiality
High
Availability
None
Scope
Unchanged
RC
Changed
RL
O
E
Unchanged

Affected products