CVE-2020-4243: Medium severity ibm security identity governance and intelligence vulnerability
IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens. IBM X-Force ID: 175420.
Other sources
IBM Security Identity Governance Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-4243.
What is the severity of CVE-2020-4243?
The severity of CVE-2020-4243 is medium.
How can a remote attacker exploit CVE-2020-4243?
A remote attacker can exploit CVE-2020-4243 by performing man-in-the-middle techniques to obtain sensitive information.
Which version of IBM Security Identity Governance and Intelligence is affected by CVE-2020-4243?
IBM Security Identity Governance and Intelligence version 5.2.6 is affected by CVE-2020-4243.
Is there a fix available for CVE-2020-4243?
Yes, IBM has provided a fix for CVE-2020-4243. Please refer to the IBM support page for more information.