CVE-2020-4340: Medium severity ibm security secret server vulnerability
Published Sep 16, 2020
·Updated
IBM Security Secret Server could allow an attacker to bypass SSL security due to improper certificate validation.
Other sources
IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180.
Affected Software
2 affected components
IBM Security Secret Server<10.9
Microsoft Windows
Event History
Sep 16, 2020
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Sep 23, 2020
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this IBM Security Secret Server vulnerability?
The vulnerability ID is CVE-2020-4340.
2
What is the severity of CVE-2020-4340?
The severity of CVE-2020-4340 is medium (4.3).
3
How does the vulnerability in IBM Security Secret Server allow bypassing SSL security?
The vulnerability in IBM Security Secret Server allows bypassing SSL security due to improper certificate validation.
4
What is the IBM X-Force ID associated with this vulnerability?
The IBM X-Force ID associated with this vulnerability is 178180.
5
How can I fix the SSL security bypass vulnerability in IBM Security Secret Server?
To fix the SSL security bypass vulnerability in IBM Security Secret Server, update to version 10.9 or higher.