A security vulnerability identified on IBM Security Secret Server has been addressed in the release 10.8.
CVEID:CVE-2020-4459
**DESCRIPTION:**IBM Security Verify Access contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/181395 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Security Secret Server | All |
Upgrade IBM Security Secret Server to version 10.8 as per the instructions here.
None