CVE-2021-20488 PUBLISHED CVSS 7.5 HIGH

IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.

EPSS 0.19% · 41.0th percentile

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/C:H/PR:L/UI:N/A:H/S:U/AC:H/I:H/E:U/RL:O/RC:C
EPSS Score
0.19%
41.0th percentile

Affected Products

VendorProductVersions
IBMSecurity Identity Manager6.0.2
ibmsecurity_identity_manager6.0.2

Timeline

References

Open in Interactive Console →