First published: Tue Dec 22 2020(Updated: )
IBM Security Identity Governance and Intelligence 5.2.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192427.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Governance and Intelligence | =5.2.6 | |
<=5.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4968.
The title of the vulnerability is "IBM Security Identity Governance Virtual Appliance uses weaker than expected cryptographic algorithm…".
The vulnerability allows an attacker to decrypt highly sensitive information by exploiting weaker than expected cryptographic algorithms in IBM Security Identity Governance and Intelligence 5.2.6. The IBM X-Force ID for this vulnerability is 192427.
IBM Security Identity Governance and Intelligence version 5.2.6 is affected.
The severity of this vulnerability is medium and it has a CVSS score of 6.5.
To fix this vulnerability, it is recommended to update to a version of IBM Security Identity Governance and Intelligence that uses stronger cryptographic algorithms.
You can find more information about this vulnerability on the IBM X-Force Exchange website (ID: 192427) and the IBM Support website.
The Common Weakness Enumeration (CWE) ID associated with this vulnerability is CWE-327.