Information exposure through externally-generated error message in IBM Security Identity Governance and Intelligence (IGI) - CVE-2020-4248

 

Information exposure through externally-generated error message in IBM Security Identity Governance and Intelligence (IGI) - CVE-2020-4248

Published: May 29, 2020


Vulnerability identifier: #VU28361
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4248
CWE-ID:
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application while handling error conditions. A remote user can obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.


Affected software

IBM Security Identity Governance and Intelligence (IGI)

How to mitigate CVE-2020-4248

Install updates from vendor's website.


External References

Related Security Bulletins