First published: Fri Dec 11 2020(Updated: )
IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used in further attacks against the system. IBM X-Force ID: 192425.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.3.0.1 | ||
<=1.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4967 has a medium severity rating due to its potential to disclose sensitive information.
To fix CVE-2020-4967, you should update IBM Cloud Pak for Security to the latest version that addresses this vulnerability.
CVE-2020-4967 affects IBM Cloud Pak for Security version 1.3.0.1 and potentially earlier versions.
CVE-2020-4967 can disclose sensitive information through HTTP headers, which can be leveraged for further attacks.
Currently, no specific workarounds have been publicly recommended for CVE-2020-4967, so updating the software is advised.