First published: Thu Nov 05 2020(Updated: )
IBM Cloud Pak for Security (CP4S) could reveal sensitive information about the internal network to an authenticated user using a specially crafted HTTP request.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.3.0.1 | ||
<=1.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4626 is medium.
CVE-2020-4626 can reveal sensitive information about the internal network to an authenticated user using a specially crafted HTTP request in IBM Cloud Pak for Security (CP4S).
IBM Cloud Pak for Security (CP4S) version 1.3.0.1 is affected by CVE-2020-4626.
To fix the vulnerability CVE-2020-4626 in IBM Cloud Pak for Security (CP4S), update to a version that is not affected, if available, or follow the guidance provided by IBM.
You can find more information about the vulnerability CVE-2020-4626 on the IBM X-Force ID: 185362 page and the IBM support page.