First published: Thu Nov 05 2020(Updated: )
IBM Cloud Pak for Security (CP4S) uses weaker than expected cryptographic algorithms during negotiation could allow an attacker to decrypt sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.3.0.1 | ||
<=1.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4624 has a medium severity rating due to the potential for sensitive information to be decrypted.
To fix CVE-2020-4624, upgrade IBM Cloud Pak for Security to a version that uses stronger cryptographic algorithms.
The impacts of CVE-2020-4624 include unauthorized decryption of sensitive data, which could lead to data breaches.
CVE-2020-4624 affects IBM Cloud Pak for Security version 1.3.0.1.
There are currently no recommended workarounds for mitigating CVE-2020-4624; upgrading is the preferred solution.