Lucene search

K
ibmIBMF4B92C2C7C261293CB32CA0733CF51D8280EF3800291C33567FA55909EC77901
HistoryMar 03, 2020 - 7:53 a.m.

Security Bulletin: A security vulnerability has been addressed in IBM Security Privileged Identity Manager

2020-03-0307:53:00
www.ibm.com
18

0.024 Low

EPSS

Percentile

89.9%

Summary

IBM Security Privileged Identity Manager has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2018-15473
**DESCRIPTION:**OpenSSH could allow a remote attacker to obtain sensitive information, caused by different responses to valid and invalid authentication attempts. By sending a specially crafted request, an attacker could exploit this vulnerability to enumerate valid usernames.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/148397 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
ISPIM 2.1.0
ISPIM 2.0.2

Remediation/Fixes

Product VRMF Remediation
IBM Security Privileged Identity Manager 2.1.0 - 2.1.0.10 2.1.0-ISS-ISPIM-VA-IF0011
IBM Security Privileged Identity Manager 2.0.2 - 2.0.2.11 2.0.2-ISS-ISPIM-VA-IF0012

Workarounds and Mitigations

None