Lucene search

K
ibmIBM2AE9034AD132494C985ADB5175DCDF862137EE13DCDEBAEAA6CD3225526024C8
HistoryMay 10, 2021 - 5:17 p.m.

Security Bulletin: IBM OpenPages with Watson has addressed an information disclosure vulnerability (CVE-2020-4536)

2021-05-1017:17:12
www.ibm.com
10
ibm openpages
watson
information disclosure vulnerability
fixed

EPSS

0.001

Percentile

32.8%

Summary

IBM OpenPages with Watson has addressed an information disclosure vulnerability caused by improper validation.

Vulnerability Details

CVEID:CVE-2020-4536
**DESCRIPTION:**IBM OpenPages with Watson could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/182907 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM OpenPages with Watson version v8.1

Remediation/Fixes

A fix has been created for each affected version of the named product. Download and install the fix as soon as possible. Fixes and installation instructions are provided at the URL listed below:

Fix Download URL
For IBM OpenPages with Watson 8.1
- Apply 8.1.0.2 or later <https://www.ibm.com/support/pages/openpages-watson-81-fix-pack-2&gt;

Workarounds and Mitigations

None

EPSS

0.001

Percentile

32.8%

Related for 2AE9034AD132494C985ADB5175DCDF862137EE13DCDEBAEAA6CD3225526024C8