First published: Tue Jul 28 2020(Updated: )
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184179.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Key Lifecycle Manager | =3.0.1 | |
Ibm Security Key Lifecycle Manager | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4572 is a vulnerability found in IBM Tivoli Key Lifecycle Manager versions 3.0.1 and 4.0.
A remote attacker can exploit CVE-2020-4572 by obtaining sensitive information when a detailed technical error message is returned in the browser.
CVE-2020-4572 has a severity rating of 5.3, which is considered medium.
IBM Tivoli Key Lifecycle Manager versions 3.0.1 and 4.0 are affected by CVE-2020-4572.
To fix CVE-2020-4572, update IBM Tivoli Key Lifecycle Manager to a version that is not affected by the vulnerability.