Lucene search

K
ibmIBM7A52B739DAB04F18156A2E79E86AEF58DC483064724ADDBF7E6EC3D545012A80
HistoryJan 26, 2021 - 5:23 p.m.

Security Bulletin: IBM Cloud Pak for Security is potentially vulnerable to sensitive information exposure (CVE-2020-4816)

2021-01-2617:23:10
www.ibm.com
10
ibm
cloud pak for security
1.4.0.0
vulnerability
sensitive information exposure
cve-2020-4816
http strict transport security
man in the middle
upgrade

EPSS

0.002

Percentile

56.0%

Summary

IBM Cloud Pak for Security 1.4.0.0 could allow a remote attacker to obtain sensitive information. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. This has been addressed in an update.

Vulnerability Details

CVEID:CVE-2020-4816
**DESCRIPTION:**IBM Cloud Pak for Security (CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/189703 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Cloud Pak for Security (CP4S) 1.4.0.0

Remediation/Fixes

Upgrade to CP4S 1.5.0.0 or greater at <https://cloud.ibm.com/catalog/content/ibm-cp-security-b25bd169-0fbd-4cf3-a8ea-0067316158a4-global&gt; or following <https://www.ibm.com/support/knowledgecenter/en/SSTDPP_1.5.0/platform/docs/security-pak/upgrading.html&gt;

Workarounds and Mitigations

None

EPSS

0.002

Percentile

56.0%

Related for 7A52B739DAB04F18156A2E79E86AEF58DC483064724ADDBF7E6EC3D545012A80