First published: Fri Nov 13 2020(Updated: )
IBM Cloud Pak for Security (CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.3.0.1 | ||
IBM Cloud Pak for Security (CP4S) | <=1.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-4625.
The severity of CVE-2020-4625 is medium with a score of 5.3.
A remote attacker can exploit CVE-2020-4625 to obtain sensitive information from the cookie.
The affected version of IBM Cloud Pak for Security (CP4S) is 1.3.0.1.
To fix CVE-2020-4625, IBM Cloud Pak for Security (CP4S) should set the HTTPOnly flag.