High Severity

Security Bulletin: IBM Security Verify Password Synchronization Plug-in for Windows AD affected by multiple vulnerabilities (CVE-2021-20488, CVE-2021-20494, CVE-2021-20572, CVE-2021-20573, CVE-2021-20574)

Share this post:

IBM has announced a release for IBM Security Verify Password Synchronization Plug-in for Windows AD to address several security vulnerabilities. The vulnerabilities concern denial of service and account take over.

CVE(s): CVE-2021-20572, CVE-2021-20494, CVE-2021-20574, CVE-2021-20488, CVE-2021-20573

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
IBM Security Identity Manager Adapters 6.0, 7.0

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6465875
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/199247
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/197882
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/199252
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/197789
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/199249

More stories

Security Bulletin: Apache log4j vulnerabilities in Spark and Zookeeper affect QRadar User Behavior Analytics(CVE-2021-4104)

August 5, 2022 | High Severity

There is a vulnerability in Apache log4j used by Spark and Zookeeper that is affecting QRadar User Behavior Analytics(UBA). This has been addressed in both dependencies and UBA has been updated to the patched versions. ...read more


Security Bulletin: Multiple vulnerabilities in Jquery-Ui, highcharts, and datatables are affecting QRadar User Behavior Analytics (CVE-2021-41182, CVE-2021-41183, CVE-2021-41184, CVE-2021-23445, CVE-2021-29489)

August 5, 2022 | High Severity

There are vulnerabilities in third party packages (JQuery-UI, Highcharts, datatables.net) affecting User Behavior Anaytics(UBA). UBA has been updated to the latest versions of these packages to address these vulnerabilities. ...read more


Security Bulletin: IBM Sterling Connect:Direct for UNIX Certified Container is affected by denial of service vulnerability in version 1.1.1k-5

August 4, 2022 | High Severity

IBM Sterling Connect:Direct for UNIX Certified Container requires openssl for LDAP support. This fix upgrades the openssl and its compnent packages to version 1.1.1k-6.el8_5 ...read more