CVE-2020-4696: Medium severity ibm cloud pak for security vulnerability
IBM Cloud Pak for Security (CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session.
Other sources
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 186789.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4696?
CVE-2020-4696 is rated as a medium severity vulnerability due to its potential to expose sensitive user information.
How do I fix CVE-2020-4696?
To fix CVE-2020-4696, upgrade to IBM Cloud Pak for Security version 1.3.1 or later, which addresses the session invalidation issue.
What are the potential impacts of CVE-2020-4696?
The potential impact of CVE-2020-4696 includes unauthorized access to sensitive information from a previous session if a user does not fully log out.
Who is affected by CVE-2020-4696?
CVE-2020-4696 affects users of IBM Cloud Pak for Security version 1.3.0.1 and earlier.
Is there a workaround for CVE-2020-4696?
A temporary workaround for CVE-2020-4696 is to ensure users manually clear their session data before logging out.