First published: Fri Nov 20 2020(Updated: )
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 189214.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | >=10.1.0<=10.1.6 | |
Linux Linux kernel | ||
<=10.1.0-10.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4783.
The severity of CVE-2020-4783 is medium.
CVE-2020-4783 occurs due to the failure to properly enable HTTP Strict Transport Security in IBM Spectrum Protect Plus 10.1.0 through 10.1.6.
An attacker can exploit CVE-2020-4783 to obtain sensitive information using man-in-the-middle techniques.
Yes, there is a fix available for CVE-2020-4783. Please refer to the official IBM support page for more details.