PT-2022-10872 · Ibm · Ibm Security Verify Access

Published

2022-02-02

·

Updated

2022-07-12

·

CVE-2021-39070

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Verify Access versions 10.0.0.0 through 10.0.2.0
Description The issue allows an attacker to authenticate as any user on the system when the advanced access control authentication service is enabled.
Recommendations For versions 10.0.0.0 through 10.0.2.0, disable the advanced access control authentication service as a temporary workaround until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-39070

Affected Products

Ibm Security Verify Access