Lucene search

K
ibmIBM65B442CBF565D36CA75143C282746E7DE4CC4D29AA0A635F819FB2665024B11B
HistoryNov 10, 2021 - 8:19 a.m.

Security Bulletin: IBM Security SiteProtector System is affected by vulnerability CVE-2020-4146

2021-11-1008:19:28
www.ibm.com
8
ibm security siteprotector
vulnerability
cve-2020-4146
fix

EPSS

0.001

Percentile

41.6%

Summary

IBM Security SiteProtector System has addressed the following vulnerabilities in Core XPU

Vulnerability Details

CVEID:CVE-2020-4146
**DESCRIPTION:**IBM SiteProtector Appliance could allow a remote attacker to obtain sensitive information, caused by missing ‘HttpOnly’ flag. A remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174129 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security SiteProtector System 3.1.1

Remediation/Fixes

Product
| VRMF
| Remediation/First Fix

—|—|—
IBM Security SiteProtector System| 3.1.1
| Apply the appropriate eXPress Updates (XPUs) as identified in the SiteProtector Console Agent view:

ServicePack3_1_1_23.xpu

Workarounds and Mitigations

None

EPSS

0.001

Percentile

41.6%

Related for 65B442CBF565D36CA75143C282746E7DE4CC4D29AA0A635F819FB2665024B11B