CVE-2020-4843: Medium severity ibm security secret server vulnerability
Published Dec 21, 2020
·Updated
IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authenticated user. IBM X-Force ID: 190048.
Affected Software
2 affected components
IBM Security Secret Server=10.6
Microsoft Windows
Remediation
Patch Available
Event History
Dec 21, 2020
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for IBM Security Secret Server 10.6?
The vulnerability ID for IBM Security Secret Server 10.6 is CVE-2020-4843.
2
What is the severity rating of CVE-2020-4843?
CVE-2020-4843 has a severity rating of 4.3 (medium).
3
What is the impact of the vulnerability in IBM Security Secret Server 10.6?
The vulnerability in IBM Security Secret Server 10.6 allows an authenticated user to read potentially sensitive information.
4
How can an authenticated user exploit the vulnerability in IBM Security Secret Server 10.6?
An authenticated user can exploit the vulnerability in IBM Security Secret Server 10.6 by reading the sensitive information stored in config files.
5
Is IBM Security Secret Server 10.6 the only affected software?
No, IBM Security Secret Server 10.6 is the affected software, and it runs on Microsoft Windows.