CVE-2020-4628: Medium severity ibm cloud pak for security vulnerability
IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 185369.
Other sources
IBM Cloud Pak for Security (CP4S) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4628?
CVE-2020-4628 has been classified as medium severity due to the potential for sensitive information disclosure.
How do I fix CVE-2020-4628?
To fix CVE-2020-4628, you should upgrade IBM Cloud Pak for Security to the latest version that addresses this vulnerability.
What systems are affected by CVE-2020-4628?
IBM Cloud Pak for Security versions 1.3.0.1 and 1.4.0.0 are the affected systems for CVE-2020-4628.
What type of vulnerability is CVE-2020-4628?
CVE-2020-4628 is an information disclosure vulnerability that can occur due to detailed error messages being returned by the application.
Can CVE-2020-4628 be exploited remotely?
Yes, CVE-2020-4628 can be exploited remotely by an attacker who can trigger the system to return detailed error messages.