CVE-2020-4626: Medium severity IBM Cloud Pak for Security vulnerability
IBM Cloud Pak for Security (CP4S) could reveal sensitive information about the internal network to an authenticated user using a specially crafted HTTP request.
Other sources
IBM Cloud Pak for Security 1.3.0.1 (CP4S) could reveal sensitive information about the internal network to an authenticated user using a specially crafted HTTP request. IBM X-Force ID: 185362.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4626?
The severity of CVE-2020-4626 is medium.
How does CVE-2020-4626 impact IBM Cloud Pak for Security (CP4S)?
CVE-2020-4626 can reveal sensitive information about the internal network to an authenticated user using a specially crafted HTTP request in IBM Cloud Pak for Security (CP4S).
Which version of IBM Cloud Pak for Security (CP4S) is affected by CVE-2020-4626?
IBM Cloud Pak for Security (CP4S) version 1.3.0.1 is affected by CVE-2020-4626.
How can I fix the vulnerability CVE-2020-4626 in IBM Cloud Pak for Security (CP4S)?
To fix the vulnerability CVE-2020-4626 in IBM Cloud Pak for Security (CP4S), update to a version that is not affected, if available, or follow the guidance provided by IBM.
Where can I find more information about the vulnerability CVE-2020-4626?
You can find more information about the vulnerability CVE-2020-4626 on the IBM X-Force ID: 185362 page and the IBM support page.