CVE-2021-29676
CVE-2021-29676
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.6EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
25 jun 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking
CVSS:3.0/I:L/AV:N/A:N/PR:L/AC:L/C:L/S:U/UI:R/E:U/RL:O/RC:C
Productos afectados
IBM · Security Verify Privilege Vault