CVE-2020-4783: Medium severity ibm storage protect plus vulnerability
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 189214.
Other sources
IBM Spectrum Protect Plus could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4783.
What is the severity of CVE-2020-4783?
The severity of CVE-2020-4783 is medium.
How does CVE-2020-4783 occur?
CVE-2020-4783 occurs due to the failure to properly enable HTTP Strict Transport Security in IBM Spectrum Protect Plus 10.1.0 through 10.1.6.
How can an attacker exploit CVE-2020-4783?
An attacker can exploit CVE-2020-4783 to obtain sensitive information using man-in-the-middle techniques.
Is there a fix available for CVE-2020-4783?
Yes, there is a fix available for CVE-2020-4783. Please refer to the official IBM support page for more details.