CVE-2021-39090

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Feb 29, 2024
Updated: Dec 31, 2024
CWE ID 311
CWE ID 319

Summary

CVE-2021-39090 is a vulnerability affecting IBM Cloud Pak for Security (CP4S) versions 1.10.0.0 through 1.10.6.0. This issue allows a remote attacker to obtain sensitive information due to insufficient HTTP Strict Transport Security (HSTS) configuration. An attacker could exploit this weakness through man-in-the-middle techniques to gain access to sensitive data. IBM X-Force has assigned ID 216388 to this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share