First published: Fri Mar 19 2021(Updated: )
IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security SOAR | =40.0 | |
Red Hat Enterprise Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4635 is rated as a medium severity vulnerability due to its potential for unauthorized information disclosure.
To mitigate CVE-2020-4635, upgrade to a patched version of IBM Resilient SOAR beyond version 40.0.
CVE-2020-4635 allows attackers to enumerate valid usernames, potentially leading to further attacks.
CVE-2020-4635 affects IBM Resilient SOAR version 40.0 and earlier.
No specific workaround is provided for CVE-2020-4635; the recommended action is to upgrade to the latest version.