Lucene search

K
ibmIBMF37946B71296D08AF6EA663F8A24655ECEF06F07958187FFA36288FF50161CDA
HistoryMar 23, 2020 - 3:40 p.m.

Security Bulletin: IBM Content Navigator includes the host IP address in an HTTP response.

2020-03-2315:40:02
www.ibm.com
9

0.001 Low

EPSS

Percentile

27.9%

Summary

IBM Content Navigator has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2020-4309
**DESCRIPTION:**IBM Content Navigator could disclose sensitive information to an unauthenticated user which could be used to aid in further attacks against the system.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177080 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Content Navigator 3.0CD

Remediation/Fixes

Product VMRF Remediation / First Fix
IBM Content Navigator 3.0 Continuous Delivery 3.0.6. IF6 and above, 3.0.7 IF 2 and above

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm content navigatoreq3.0

0.001 Low

EPSS

Percentile

27.9%

Related for F37946B71296D08AF6EA663F8A24655ECEF06F07958187FFA36288FF50161CDA