Information Disclosure in IBM Verify Gateway by IBM
CVE-2020-4397

6.8MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
22 July 2020

Summary

The IBM Verify Gateway versions 1.0.0 and 1.0.1 transmit sensitive information in an unsecured plain text format. This vulnerability allows attackers to intercept and access exposed data using man-in-the-middle techniques, potentially compromising sensitive information and overall system integrity.

Affected Version(s)

Verify Gateway (IVG) 1.0.0

Verify Gateway (IVG) 1.0.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.