CVE-2021-39090
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Published Feb 29, 2024
Updated: Dec 31, 2024
CWE ID 311
CWE ID 319
Summary
CVE-2021-39090 is a vulnerability affecting IBM Cloud Pak for Security (CP4S) versions 1.10.0.0 through 1.10.6.0. This issue allows a remote attacker to obtain sensitive information due to insufficient HTTP Strict Transport Security (HSTS) configuration. An attacker could exploit this weakness through man-in-the-middle techniques to gain access to sensitive data. IBM X-Force has assigned ID 216388 to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation