CVE-2021-39070

CRITICAL

IBM Security Verify Access <10.0.2.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6552318
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/215353

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 71.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (6)
ibm/security_verify_access 10.0.0
ibm/security_verify_access 10.0.1.0
ibm/security_verify_access 10.0.2.0
ibm/security_verify_access_docker 10.0.0
ibm/security_verify_access_docker 10.0.1.0
ibm/security_verify_access_docker 10.0.2.0
Published Feb 02, 2022
Tracked Since Feb 18, 2026