PT-2021-18405 · Ibm · Ibm Security Identity Manager

Published

2021-05-20

·

Updated

2021-05-24

·

CVE-2021-29683

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Identity Manager version 7.0.2
Description The issue allows an authenticated user to read user credentials stored in plain clear text.
Recommendations For IBM Security Identity Manager version 7.0.2, update to a version that stores user credentials securely, or consider implementing additional access controls to limit the ability of authenticated users to read sensitive data.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29683

Affected Products

Ibm Security Identity Manager