PT-2021-14058 · Ibm · Ibm Security Verify Access
Published
2021-05-31
·
Updated
2021-06-04
·
CVE-2021-20585
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Security Verify Access version 20.07
Description:
The issue could disclose sensitive information in HTTP server headers, potentially leading to further attacks against the system.
Recommendations:
For IBM Security Verify Access version 20.07, consider restricting access to sensitive information in HTTP server headers until a patch is available. As a temporary workaround, review and modify server header configurations to minimize the disclosure of sensitive information.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Verify Access