Input Masking Flaw in IBM QRadar Advisor Affects Multiple Versions
CVE-2020-4408
4.2MEDIUM
Summary
An input masking flaw exists in the IBM QRadar Advisor with Watson App for IBM QRadar SIEM, spanning versions 1.1 to 2.5.2. This vulnerability allows passwords entered into the input fields to be inadequately masked, posing a risk of exposure to a physical attacker located nearby. Without proper masking, sensitive data could be accessed by unauthorized individuals, heightening the need for vigilance in environments where the software is deployed.
Affected Version(s)
Qradar Advisor 1.1
Qradar Advisor 2.5.2
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved