Rewterz
Rewterz Threat Advisory – CVE-2021-22930 – Node.js close http2 Vulnerability
July 30, 2021
Rewterz
Rewterz Threat Advisory –CVE-2021-29736 – IBM WebSphere Application Server Security Vulnerability
July 30, 2021

Rewterz Threat Advisory –CVE- 2021-20505 – IBM Power System Information Disclosure

Severity

Medium

Analysis Summary

CVE-2021-20505

The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic

Impact

  • Information disclosure

Affected Vendors

IBM

Affected Products

  • IBM PowerVM Hypervisor FW930
  • IBM PowerVM Hypervisor FW920
  • IBM PowerVM Hypervisor FW940

Remediation

Refer to the appropriate IBM Security Bulletin for the patch, upgrade, or suggested workaround information.

https://www.ibm.com/support/pages/node/6475619