First published: Mon Aug 03 2020(Updated: )
IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 181395.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Secret Server | <=All | |
IBM Security Secret Server | <10.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4459 refers to a vulnerability in IBM Security Verify Access 10.7 where it contains hard-coded credentials, such as a password or cryptographic key.
CVE-2020-4459 has a severity keyword of 'critical' and a severity value of 9.8.
IBM Security Secret Server versions up to and including 10.8 are affected by CVE-2020-4459.
The CWE ID of CVE-2020-4459 is 798.
To fix CVE-2020-4459, it is recommended to update IBM Security Verify Access to a patched version that no longer contains the hard-coded credentials.