CVE-2020-5021: Medium severity IBM Spectrum Protect Plus vulnerability
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.
Other sources
IBM Spectrum Protect Plus does not invalidate session after a password reset which could allow a local user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5021.
What is the severity of CVE-2020-5021?
CVE-2020-5021 has a severity value of 4.4, which is classified as medium.
What is the description of CVE-2020-5021?
CVE-2020-5021 is a vulnerability in IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6 that allows a local user to impersonate another user on the system after a password reset.
What software versions are affected by CVE-2020-5021?
IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6 are affected by CVE-2020-5021.
Is Linux kernel vulnerable to CVE-2020-5021?
No, the Linux kernel is not vulnerable to CVE-2020-5021.