Lucene search

K
ibmIBMAF046D771C2EB49E63F2B60954EBB28A9A0468FD68D516C56F54B968D41EB9E2
HistoryAug 03, 2020 - 3:13 p.m.

Security Bulletin: A Security Vulnerability Has Been Identified In IBM Security Secret Server (CVE-2020-4459)

2020-08-0315:13:07
www.ibm.com
11

EPSS

0.001

Percentile

46.2%

Summary

A security vulnerability identified on IBM Security Secret Server has been addressed in the release 10.8.

Vulnerability Details

CVEID:CVE-2020-4459
**DESCRIPTION:**IBM Security Verify Access contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/181395 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Secret Server All

Remediation/Fixes

Upgrade IBM Security Secret Server to version 10.8 as per the instructions here.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

46.2%

Related for AF046D771C2EB49E63F2B60954EBB28A9A0468FD68D516C56F54B968D41EB9E2