VDB
CVE-2021-20488
CVE-2021-20488
PUBLISHED
CVSS 7.5 HIGH
IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.
EPSS 0.19% · 41.0th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/C:H/PR:L/UI:N/A:H/S:U/AC:H/I:H/E:U/RL:O/RC:C
EPSS Score
0.19%
41.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | Security Identity Manager | 6.0.2 |
| ibm | security_identity_manager | 6.0.2 |
Exploit Intelligence
Timeline
- Jun 16, 2021 CVE Published
- Jun 17, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 18, 2021 EPSS Score
- Dec 17, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 15, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 17, 2022 EPSS Score
- Aug 17, 2022 EPSS Score
- Oct 16, 2022 EPSS Score
References
- https://www.ibm.com/support/pages/node/6464409 advisory
- https://www.ibm.com/support/pages/node/6464423 advisory
- https://www.ibm.com/support/pages/node/6464081 advisory
- https://www.ibm.com/support/pages/node/6463985 advisory
- https://www.ibm.com/support/pages/node/6445497 advisory
- https://www.ibm.com/support/pages/node/6463165 advisory
- ibm-sim-cve202120488-gain-access (197789) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2021-20488 advisory