PT-2021-18439 · Ibm · Ibm Infosphere Information Server
Robin Trost
·
Published
2021-11-02
·
Updated
2021-11-03
·
CVE-2021-29737
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM InfoSphere Information Server version 11.7
Description
The issue is related to improper validation of the REST API server certificate in the IBM InfoSphere Data Flow Designer Engine component. This could potentially allow for man-in-the-middle attacks or other security breaches. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations
For IBM InfoSphere Information Server version 11.7, update the component to properly validate the REST API server certificate. As a temporary workaround, consider restricting access to the REST API until a patch is available.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Infosphere Information Server