CVE-2020-4965: High severity IBM Collaborative Lifecycle Management vulnerability
IBM Jazz Foundation uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4965?
CVE-2020-4965 is classified as a medium severity vulnerability due to its potential to allow decryption of sensitive information.
How do I fix CVE-2020-4965?
To fix CVE-2020-4965, upgrade to the appropriate patched version of the affected IBM products listed in the vulnerability details.
What products are affected by CVE-2020-4965?
CVE-2020-4965 affects several IBM products including IBM RDNG, IBM DOORS Next, and IBM RQM among others.
What are the potential impacts of CVE-2020-4965?
The potential impacts of CVE-2020-4965 include unauthorized decryption of highly sensitive information, posing a risk to data confidentiality.
Is there a workaround for CVE-2020-4965?
While the best approach is to apply patches, consult IBM support for possible temporary workarounds to mitigate the impact of CVE-2020-4965.