CVE-2020-4169: High severity IBM Security Guardium Insights vulnerability
Published Aug 21, 2020
·Updated
IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174405.
Affected Software
4 affected componentsFixes available
IBM Security Guardium Insights=2.0.1
IBM Initial Release<=2.0
IBM Initial Release<=2.0
IBM Security Guardium Insights<=2.0.1
Remediation
Patch Available
Event History
Aug 21, 2020
CVE Published
via IBM·12:00 AM
Aug 27, 2020
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4169.
2
What is the severity of CVE-2020-4169?
The severity of CVE-2020-4169 is high with a CVSS score of 7.5.
3
How can an attacker exploit CVE-2020-4169?
An attacker can exploit CVE-2020-4169 by using weaker than expected cryptographic algorithms to decrypt highly sensitive information.
4
What software versions are affected by CVE-2020-4169?
IBM Security Guardium Insights versions up to and inclusive of 2.0.1 are affected by CVE-2020-4169.
5
How can I fix CVE-2020-4169?
To fix CVE-2020-4169, update to a version of IBM Security Guardium Insights higher than 2.0.1 by applying the available patch provided by IBM.