Medium
CVE-2021-39089 CVSS:4.3
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request.
CVE-2021-39011 CVSS:4.2
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user.
IBM
Refer to IBM Security Bulletin for patch, upgrade or suggested workaround information.