CVE-2020-4815: Infoleak
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response headers that could be used in further attacks against the system.
Other sources
IBM Cloud Pak for Security (CP4S) could allow a remote user to obtain sensitive information from HTTP response headers that could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4815?
CVE-2020-4815 is categorized with a medium severity level due to the potential exposure of sensitive information.
How do I fix CVE-2020-4815?
To fix CVE-2020-4815, upgrade IBM Cloud Pak for Security to a version higher than 1.4.0.0.
What type of vulnerability is CVE-2020-4815?
CVE-2020-4815 is an information disclosure vulnerability allowing remote users to access sensitive data from HTTP response headers.
Who is affected by CVE-2020-4815?
Organizations utilizing IBM Cloud Pak for Security version 1.4.0.0 are potentially affected by CVE-2020-4815.
Can CVE-2020-4815 lead to further attacks?
Yes, the information obtained from CVE-2020-4815 can be leveraged for subsequent attacks against the system.