First published: Wed Apr 28 2021(Updated: )
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a privileged user to inject inject malicious data using a specially crafted HTTP request due to improper input validation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security (CP4S) | <=1.6.0.1 | |
IBM Cloud Pak for Security (CP4S) | <=1.6.0.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.5.0.1 | |
IBM Cloud Pak for Security (CP4S) | <=1.5.0.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.4.0.0 | |
IBM Cloud Pak for Security | =1.4.0.0 | |
IBM Cloud Pak for Security | =1.5.0.0 | |
IBM Cloud Pak for Security | =1.5.0.1 | |
IBM Cloud Pak for Security | =1.6.0.0 | |
IBM Cloud Pak for Security | =1.6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4811.
The severity of CVE-2020-4811 is medium, with a severity value of 2.4.
IBM Cloud Pak for Security (CP4S) versions 1.4.0.0 to 1.6.0.1 are affected.
The vulnerability in IBM Cloud Pak for Security (CP4S) occurs when a privileged user injects malicious data using a specially crafted HTTP request due to improper input validation.
To fix the vulnerability in IBM Cloud Pak for Security (CP4S), it is recommended to apply the necessary security patches or updates provided by IBM.