LiveActive security incident?Get immediate response
CVE Record

CVE-2021-20422: IBM Cloud Pak for Applications 4.3 could disclose sensitive information to a malicious attacker by accessin...

IBM Cloud Pak for Applications 4.3 could disclose sensitive information to a malicious attacker by accessing data stored in memory. IBM X-Force ID: 196304.

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

IBM Cloud Pak for Applications 4.3 can expose sensitive information from memory to a malicious attacker. The business concern is confidentiality: secrets, tenant data, or operational details may be disclosed if vulnerable deployments are reachable. The provided sources do not identify other affected versions or confirmed active exploitation.

Executive priority

Treat this as a high-priority confidentiality issue for any IBM Cloud Pak for Applications 4.3 environment. It is not currently KEV-listed in the provided data, but the unauthenticated network profile and high confidentiality impact justify prompt inventory, vendor-guided remediation, and access review.

Technical view

CVE-2021-20422 is an IBM Cloud Pak for Applications 4.3 information disclosure issue involving data stored in memory. CVSS 3.0 score is 7.5 with network attack vector, low complexity, no privileges, no user interaction, high confidentiality impact, and no integrity or availability impact.

Likely exposure

Exposure is limited, based on the bundle, to IBM Cloud Pak for Applications version 4.3. Prioritize externally reachable or broadly accessible deployments first, then internal deployments handling sensitive application or platform data.

Exploitation context

The bundle marks CISA KEV as false and CVSS exploit code maturity as unproven. No provided source states active exploitation. The CVSS vector indicates a network-reachable issue requiring no privileges or user interaction, which raises triage urgency despite incomplete exploit evidence.

Researcher notes

Evidence is sparse: no CWE is listed, and the bundle does not describe the vulnerable component or memory-access condition. Avoid assuming exploitability details beyond the CVSS vector and IBM description. Validate exposure through asset inventory and vendor advisory mapping, not speculative testing.

Mitigation direction

  • Identify all IBM Cloud Pak for Applications 4.3 deployments.
  • Review IBM advisory 6471327 for the official remediation path.
  • Apply IBM-provided remediation after normal change testing.
  • Restrict network access to vulnerable deployments until remediated.
  • Monitor vendor guidance for updated affected-version or fix details.

Validation and detection

  • Confirm deployed IBM Cloud Pak for Applications version numbers.
  • Check whether version 4.3 is present in production or test environments.
  • Verify remediation status against IBM advisory 6471327.
  • Review logs for unusual access around affected services.
  • Document any compensating network restrictions still in place.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-20422 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/I:N/AC:L/A:N/UI:N/PR:N/C:H/AV:N/S:U/RL:O/E:U/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.0HighCVSS:3.0/I:N/AC:L/A:N/UI:N/PR:N/C:H/AV:N/S:U/RL:O/E:U/RC:C3.93.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

7.5High
CVSS 3.0 vector shape for CVE-2021-20422Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/I:N/AC:L/A:N/UI:N/PR:N/C:H/AV:N/S:U/RL:O/E:U/RC:C

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IBMCloud Pak for Applications4.3Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.