VYPR
Unrated severityNVD Advisory· Published Jul 13, 2021· Updated Sep 16, 2024

CVE-2021-20360

CVE-2021-20360

Description

IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Cloud Pak for Applications 4.3 uses weak cryptographic algorithms allowing unsecured HTTP communications, enabling attackers to decrypt sensitive data.

Vulnerability

IBM Cloud Pak for Applications version 4.3 uses weaker than expected cryptographic algorithms, resulting in unsecured HTTP communications [1]. This vulnerability affects all versions of IBM Cloud Pak for Applications prior to 4.3.1 [1]. The product fails to enforce strong encryption for network traffic, exposing sensitive data in transit.

Exploitation

An attacker with network access can perform a man-in-the-middle attack to intercept and decrypt HTTP traffic between the application and its components [1]. The attack requires high complexity due to the need for precise network positioning, but no authentication or user interaction is needed (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) [1].

Impact

Successful exploitation allows the attacker to decrypt highly sensitive information transmitted over the network, leading to a high confidentiality impact [1]. Integrity and availability are not affected.

Mitigation

IBM released version 4.3.1 of Cloud Pak for Applications, which no longer exposes unsecured HTTP communications [1]. Users should upgrade to this version. No workarounds are available [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.