A security vulnerability identified on IBM Security Secret Server has been addressed in the release 10.8.
CVEID:CVE-2020-4413
**DESCRIPTION:**IBM Security Secret Server could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/179988 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Security Secret Server | All |
Upgrade IBM Security Secret Server to version 10.8 as per the instructions here.
None