VulnerabilityModified
CVE-2021-20488
IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured.
MEDIUM 6.5EPSS 0.91%
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- ibm/security identity manager
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/197789VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6464081Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/197789VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6464081Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.