Cleartext storage of sensitive information in NGINX Controller - CVE-2021-23019
Published: May 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the NGINX Controller Administrator password is exposed via the
systemd.txt file that is included in the NGINX support package. An attacker, who can obtain the support package can retrieve administrator's password and gain unauthorized access to the system.
Affected software
IBM Cloud Pak for Business Automation
How to mitigate CVE-2021-23019
IBM Cloud Pak for Business Automation - update to 22.0.1.1