IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the HTTP Strict Transport Security (HSTS) web security policy mechanism. IBM X-Force ID: 276004.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Powersc | Ibm | 1.3 (including) | 1.3 (including) |
Powersc | Ibm | 2.0 (including) | 2.0 (including) |
Powersc | Ibm | 2.1 (including) | 2.1 (including) |