First published: Mon Jul 13 2020(Updated: )
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Verify Gateway | =1.0.0 | |
IBM Verify Gateway | =1.0.1 | |
<=PAM 1.0.0, 1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4369.
The severity of CVE-2020-4369 is medium (5.5).
The affected software is IBM Verify Gateway (IVG) version 1.0.0 and 1.0.1.
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user.
To fix CVE-2020-4369, update IBM Verify Gateway (IVG) to a version that does not store sensitive information in cleartext.