First published: Mon Jul 11 2022(Updated: )
IBM SiteProtector Appliance 3.1.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174049.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SiteProtector system | =3.1.1 | |
IBM Security SiteProtector System | <=3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4138 is classified as moderate due to the implications of unauthorized access to sensitive web pages.
To fix CVE-2020-4138, update your IBM SiteProtector Appliance to a version that addresses this vulnerability as per IBM's security advisories.
CVE-2020-4138 affects users of IBM Security SiteProtector System version 3.1.1 and prior versions.
CVE-2020-4138 is a local file access vulnerability that allows web pages stored locally to be accessible by unauthorized users.
The potential risks of CVE-2020-4138 include unauthorized access to sensitive information stored within the web pages by other users on the system.