Sensitive Information Exposure in IBM Verify Gateway by IBM
CVE-2020-4371

4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
22 July 2020

Summary

IBM Verify Gateway versions 1.0.0 and 1.0.1 are vulnerable due to the presence of sensitive information in leftover debug code. This could potentially allow a local user to exploit this information, facilitating further attacks on the system. It is crucial for organizations using this software version to assess their security measures and apply any necessary updates.

Affected Version(s)

Verify Gateway (IVG) 1.0.0

Verify Gateway (IVG) 1.0.1

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.