PT-2021-22312 · Ibm · Ibm Sterling Connect:Direct Web Services

Published

2021-11-23

·

Updated

2021-11-29

·

CVE-2021-38891

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Connect:Direct Web Services versions 1.0 through 6.0
Description The issue is related to the use of weaker than expected cryptographic algorithms, which could allow an attacker to decrypt highly sensitive information.
Recommendations For versions 1.0 through 6.0, update the cryptographic algorithms to stronger ones to prevent potential decryption of sensitive information by an attacker.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38891

Affected Products

Ibm Sterling Connect:Direct Web Services