CVE-2021-20410
MEDIUMIBM Security Verify Information Queue <1.0.8 - Info Disclosure
Title source: llmDescription
IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6414773
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/196190
Scores
CVSS v3
5.3
EPSS
0.0064
EPSS Percentile
46.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-522
Status
published
Products (2)
ibm/security_verify_information_queue
1.0.6
ibm/security_verify_information_queue
1.0.7
Published
Feb 12, 2021
Tracked Since
Feb 18, 2026