CVE-2020-4913: Infoleak
Published Nov 17, 2020
·Updated
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.
Other sources
IBM Cloud Pak System could reveal credential information in the HTTP response to a local privileged user.
Affected Software
2 affected components
IBM Cloud Pak System>=2.3.0.0<2.3.3.3
IBM Cloud Pak System<=2.3
Remediation
Patch Available
Event History
Nov 17, 2020
CVE Published
via IBM·12:00 AM
Jan 4, 2021
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4913.
2
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Cloud Pak System could reveal credential information in the HTTP response to a local privileged user.'
3
What is the severity of CVE-2020-4913?
The severity of CVE-2020-4913 is medium with a CVSS score of 4.4.
4
Which versions of IBM Cloud Pak System are affected?
IBM Cloud Pak System versions 2.3.0.0 through 2.3.3.3 are affected.
5
How can I fix the vulnerability in IBM Cloud Pak System?
To fix the vulnerability, upgrade IBM Cloud Pak System to a version higher than 2.3.3.3.