First published: Thu Aug 27 2020(Updated: )
IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Server | <=8.1.0.000-8.1.10.000 | |
IBM Spectrum Protect Server | >=8.1.0.000<=8.1.10.000 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The IBM Spectrum Protect Server could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool.
IBM Spectrum Protect Server versions 8.1.0.000 through 8.1.10.000 are affected by CVE-2020-4591.
The severity of CVE-2020-4591 is low, with a severity value of 3.3.
The second chunk of an object in an encrypted container pool can be occasionally not encrypted due to a vulnerability in IBM Spectrum Protect Server versions 8.1.0.000 through 8.1.10.000.
No, IBM AIX and Linux Linux kernel are not affected by CVE-2020-4591.