Session Token Vulnerability in IBM Security Identity Governance and Intelligence Virtual Appliance
CVE-2020-4243

3.7LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
5 August 2020

Summary

The IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance is susceptible to vulnerabilities that may allow remote attackers to leverage man-in-the-middle techniques to obtain sensitive information. This vulnerability arises from the improper invalidation of session tokens, which can lead to unauthorized access to sensitive data. Organizations using this product should ensure that they apply security best practices and implement necessary patches to safeguard against potential exploitation.

Affected Version(s)

Security Identity Governance and Intelligence 5.2.6

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.