CVE-2021-20432
CVE-2021-20432
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Apr 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 196344.
CVSS:3.0/AV:N/UI:N/I:L/S:U/A:N/C:L/PR:N/AC:L/RC:C/RL:O/E:U
Affected products
IBM · Spectrum Protect Plus