Information disclosure in Microsoft Internet Explorer - CVE-2020-1432
Published: July 14, 2020 / Updated: July 15, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to Skype for Business is accessed via Internet Explorer. A remote attacker can trick a victim to click a specially crafted URL that prompts the Skype app and gain unauthorized access to sensitive information on the system.
Affected software
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
How to mitigate CVE-2020-1432
Solutions Enabler - addressed in versions 9.1.0.12, 9.2.0.1
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.24, 9.2.0.6
Unisphere for PowerMax - addressed in versions 9.1.0.24, 9.2.0.6