CVE-2020-4967: Infoleak
IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used in further attacks against the system. IBM X-Force ID: 192425.
Other sources
IBM Cloud Pak for Security (CP4S) could disclose sensitive information through HTTP headers which could be used in further attacks against the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4967?
CVE-2020-4967 has a medium severity rating due to its potential to disclose sensitive information.
How do I fix CVE-2020-4967?
To fix CVE-2020-4967, you should update IBM Cloud Pak for Security to the latest version that addresses this vulnerability.
What systems are affected by CVE-2020-4967?
CVE-2020-4967 affects IBM Cloud Pak for Security version 1.3.0.1 and potentially earlier versions.
What information is disclosed in CVE-2020-4967?
CVE-2020-4967 can disclose sensitive information through HTTP headers, which can be leveraged for further attacks.
Is there a workaround for CVE-2020-4967?
Currently, no specific workarounds have been publicly recommended for CVE-2020-4967, so updating the software is advised.