First published: Fri Nov 13 2020(Updated: )
IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 185369.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.3.0.1 | ||
=1.4.0.0 | ||
IBM Cloud Pak for Security | <=1.4.0.0 | |
IBM Cloud Pak for Security | <=1.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4628 has been classified as medium severity due to the potential for sensitive information disclosure.
To fix CVE-2020-4628, you should upgrade IBM Cloud Pak for Security to the latest version that addresses this vulnerability.
IBM Cloud Pak for Security versions 1.3.0.1 and 1.4.0.0 are the affected systems for CVE-2020-4628.
CVE-2020-4628 is an information disclosure vulnerability that can occur due to detailed error messages being returned by the application.
Yes, CVE-2020-4628 can be exploited remotely by an attacker who can trigger the system to return detailed error messages.