PT-2021-14024 · Ibm · Ibm Security Verify Access Docker

Published

2021-07-15

·

Updated

2021-09-29

·

CVE-2021-20534

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: IBM Security Verify Access Docker version 10.0.0
Description: A remote attacker could conduct phishing attacks using an open redirect attack. The attacker could persuade a victim to visit a specially crafted Web site, exploiting this issue to spoof the URL displayed and redirect the user to a malicious Web site that appears trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Recommendations: For IBM Security Verify Access Docker version 10.0.0, consider restricting access to the affected Docker instance until a patch is available. As a temporary workaround, avoid using links from untrusted sources to minimize the risk of exploitation.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20534

Affected Products

Ibm Security Verify Access Docker