PT-2021-13930 · Ibm · Ibm Qradar User Behavior Analytics

Chris Shepherd

+7

·

Published

2021-05-14

·

Updated

2021-05-20

·

CVE-2021-20391

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM QRadar User Behavior Analytics versions 1.0.0 through 4.1.0
Description: The issue allows web pages to be stored locally, which can then be read by another user on the system.
Recommendations: For versions 1.0.0 through 4.1.0, consider restricting access to sensitive web pages or implementing additional access controls to minimize the risk of unauthorized data access.

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20391

Affected Products

Ibm Qradar User Behavior Analytics