PT-2021-13966 · Ibm · Ibm Security Verify Access Docker+1
Published
2021-07-15
·
Updated
2021-07-31
·
CVE-2021-20439
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Security Access Manager version 9.0
IBM Security Verify Access Docker version 10.0.0
Description:
The issue concerns the storage of user credentials in plain clear text, making them accessible to unauthorized users.
Recommendations:
For IBM Security Access Manager version 9.0, update the configuration to securely store user credentials.
For IBM Security Verify Access Docker version 10.0.0, modify the Docker container settings to encrypt and protect user credentials.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Access Manager
Ibm Security Verify Access Docker