VYPR
Unrated severityNVD Advisory· Published Dec 13, 2021· Updated Sep 17, 2024

CVE-2021-39052

CVE-2021-39052

Description

IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Spectrum Copy Data Management 2.2.13 and earlier allows remote attackers to access the Spring Boot console without authentication, leading to potential information disclosure and limited system compromise.

Vulnerability

IBM Spectrum Copy Data Management versions 2.2.13 and earlier contain a missing authentication vulnerability in the Spring Boot console [1]. The Spring Boot console, typically used for application monitoring and management, is exposed without proper access controls, allowing unauthenticated remote access.

Exploitation

An attacker can exploit this vulnerability by sending crafted HTTP requests to the Spring Boot console endpoints without any prior authentication [1]. The attack complexity is high (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L), meaning the attacker may need to overcome specific network conditions or timing, but no user interaction or privileges are required.

Impact

Successful exploitation allows the attacker to access the Spring Boot console, potentially leading to low-level information disclosure (e.g., application configuration, environment details), limited integrity impact (e.g., modifying certain settings), and limited availability impact (e.g., restarting services) [1]. The attack does not grant full system control.

Mitigation

IBM has not disclosed a specific fix version in the referenced advisory [1]. Users should upgrade to a version beyond 2.2.13 if available, or apply workarounds such as restricting network access to the Spring Boot console endpoints. Contact IBM support for the latest remediation guidance.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.