CVE-2020-4208: Critical severity IBM Spectrum Protect Plus vulnerability
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.
Other sources
IBM Spectrum Protect Plus contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4208?
CVE-2020-4208 is classified as a medium severity vulnerability due to the presence of hard-coded credentials.
How do I fix CVE-2020-4208?
To mitigate CVE-2020-4208, upgrade IBM Spectrum Protect Plus to version 10.1.6 or later where the hard-coded credentials issue is resolved.
What versions are affected by CVE-2020-4208?
CVE-2020-4208 affects IBM Spectrum Protect Plus from versions 10.1.0 to 10.1.5 inclusive.
What are the risks associated with CVE-2020-4208?
The risks include unauthorized access and potential data breaches due to hard-coded credentials used for authentication and encryption.
Who is responsible for addressing CVE-2020-4208?
IBM is responsible for addressing CVE-2020-4208, and users should follow their guidelines for updates and patches.