PT-2021-14024 · Ibm · Ibm Security Verify Access Docker
Published
2021-07-15
·
Updated
2021-09-29
·
CVE-2021-20534
CVSS v2.0
4.9
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Security Verify Access Docker version 10.0.0
Description:
A remote attacker could conduct phishing attacks using an open redirect attack. The attacker could persuade a victim to visit a specially crafted Web site, exploiting this issue to spoof the URL displayed and redirect the user to a malicious Web site that appears trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Recommendations:
For IBM Security Verify Access Docker version 10.0.0, consider restricting access to the affected Docker instance until a patch is available. As a temporary workaround, avoid using links from untrusted sources to minimize the risk of exploitation.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Verify Access Docker