Information Disclosure Vulnerability in IBM Security Secret Server 10.6
CVE-2020-4841
5.9MEDIUM
What is CVE-2020-4841?
IBM Security Secret Server 10.6 is susceptible to a vulnerability that allows remote attackers to retrieve sensitive information due to a deficiency in the implementation of HTTP Strict Transport Security (HSTS). This oversight can be exploited using man-in-the-middle techniques, potentially leading to unauthorized access to confidential data. Proper configuration and security measures are essential to safeguard against this type of vulnerability.
Affected Version(s)
Security Secret Server 10.6