Observable discrepancy in framework - CVE-2021-31403
Published: September 29, 2023
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to non-constant-time comparison of CSRF tokens in UIDL request handler. A local user can guess a security token for Fusion endpoints and then use this information to launch further attacks against the affected system.
Affected software
IBM Security Verify Governance
How to mitigate CVE-2021-31403
IBM Security Verify Governance - update to 10.0.1.0.4