CVE-2020-5018: High severity ibm storage protect plus vulnerability
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654.
Other sources
IBM Spectrum Protect Plus may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5018.
What is the severity level of CVE-2020-5018?
The severity level of CVE-2020-5018 is high, with a severity value of 7.5.
What is the affected software for this vulnerability?
The affected software for this vulnerability is IBM Spectrum Protect Plus version 10.1.0 through 10.1.6.
What is the risk associated with this vulnerability?
The risk associated with this vulnerability is the potential exposure of sensitive information in URLs, which can be captured by an attacker.
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update IBM Spectrum Protect Plus to version 10.1.7 or higher.