First published: Tue Jul 14 2020(Updated: )
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 179428.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Verify Gateway | =1.0.0 | |
IBM Verify Gateway | =1.0.1 | |
<=PAM 1.0.0, 1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4397 is a vulnerability in IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 that allows sensitive information to be transmitted in plain text.
An attacker can exploit CVE-2020-4397 by using man-in-the-middle techniques to intercept and obtain sensitive information transmitted in plain text.
The severity of CVE-2020-4397 is medium, with a CVSS score of 6.8.
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 are affected by CVE-2020-4397.
Yes, IBM has provided a fix for CVE-2020-4397. Please refer to the official IBM support page for instructions on how to apply the fix.