Lucene search

K
ibmIBM31F516B834D75101354B6C426376816AB0A8A6FAA51272BA62C8287657948C9B
HistoryFeb 08, 2021 - 8:25 p.m.

Security Bulletin: IBM has announced a release for IBM Security Identity Governance and Intelligence in response to a security vulnerability (CVE-2020-4995)

2021-02-0820:25:22
www.ibm.com
9
ibm
security
identity governance
intelligence
vulnerability
cve-2020-4995
access manager
session
isar ios app
cvss
affected products
remediation
fixes

EPSS

0.001

Percentile

27.9%

Summary

IBM has announced a release for IBM Security Identity Governance and Intelligence (IGI) in response to security vulnerability. The vulnerability concerns session not invalidated after logout in ISAR iOS App.

Vulnerability Details

CVEID:CVE-2020-4995
**DESCRIPTION:**IBM Security Access Manager does not invalidate session after logout which could allow a user to obtain sensitive information from another users’ session.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/192912 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Identity Governance and Intelligence 5.2.6

Remediation/Fixes

Product Name VRMF First Fix
IGI 5.2.6 10.0.0.0-ISS-ISVG-IGVA-FP0000

Workarounds and Mitigations

None

EPSS

0.001

Percentile

27.9%

Related for 31F516B834D75101354B6C426376816AB0A8A6FAA51272BA62C8287657948C9B