CVE-2020-4771: Medium severity ibm spectrum protect operations center vulnerability
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 188993.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4771?
CVE-2020-4771 is classified as a moderate severity vulnerability.
How do I fix CVE-2020-4771?
To fix CVE-2020-4771, upgrade IBM Spectrum Protect Operations Center to version 8.1.11 or later, or version 7.1.12 or later.
What impact does CVE-2020-4771 have on my system?
CVE-2020-4771 could allow a remote attacker to obtain sensitive information by exploiting improper authentication of a websocket endpoint.
Which versions are affected by CVE-2020-4771?
CVE-2020-4771 affects IBM Spectrum Protect Operations Center versions 8.1.0.000 to 8.1.10 and 7.1.0.000 to 7.1.11.
How can an attacker exploit CVE-2020-4771?
An attacker can exploit CVE-2020-4771 by using known tools to subscribe to the websocket event stream.