CVE-2020-4477: Medium severity ibm storage protect plus vulnerability
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system. IBM X-Force ID: 181779.
Other sources
IBM Spectrum Protect Plus discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4477.
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Spectrum Protect Plus discloses highly sensitive information in plain text in the virgo log file.'
What is the severity of CVE-2020-4477?
The severity of CVE-2020-4477 is medium with a severity value of 6.5.
Which software is affected by this vulnerability?
IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5 are affected by this vulnerability.
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers who gain access to the virgo log file containing highly sensitive information in plain text.