VulnerabilityModified
CVE-2021-39070
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system.
CRITICAL 9.8EPSS 1.80%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- ibm/security verify access · ibm/security verify access docker
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/215353VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6552318Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/215353VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6552318Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.