CVE-2020-4969: Medium severity ibm security identity governance and intelligence vulnerability
Published Dec 21, 2020
·Updated
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Other sources
IBM Security Identity Governance Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Affected Software
2 affected components
IBM Security Identity Governance and Intelligence=5.2.6
IBM Security Identity Governance and Intelligence<=5.2.6
Remediation
Patch Available
Event History
Dec 21, 2020
CVE Published
via IBM·12:00 AM
Jan 21, 2021
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness