First published: Tue Sep 15 2020(Updated: )
IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information from log files. IBM X-Force ID: 182658.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | <=10.0.0.0 | |
IBM DataPower Gateway | <=2018.4.1.0-2018.4.1.12 | |
IBM DataPower Gateway | >=2018.4.1.0<=2018.4.1.12 | |
IBM DataPower Gateway | =10.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM MQ Appliance vulnerability is CVE-2020-4528.
The severity of CVE-2020-4528 is medium with a severity value of 5.9.
A local user, under special conditions, can obtain highly sensitive information from log files through CVE-2020-4528.
IBM DataPower Gateway versions 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12 are affected by CVE-2020-4528.
You can find more information about CVE-2020-4528 at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/182658), [Link 2](https://www.ibm.com/support/pages/node/6333033).