Improper control of a resource through its lifetime in IBM Security Guardium Insights - CVE-2020-4172

 

Improper control of a resource through its lifetime in IBM Security Guardium Insights - CVE-2020-4172

Published: July 22, 2022


Vulnerability identifier: #VU65728
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4172
CWE-ID: CWE-664
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to IBM Security Guardium Insights stores sensitive information in URL parameters. A remote unauthenticated attacker with access to the URLs via server logs, referrer header or browser history can use this vulnerability to decrypt highly sensitive information.


Affected software

IBM Security Guardium Insights

How to mitigate CVE-2020-4172

Install updates from vendor's website.

IBM Security Guardium Insights - update to 2.0.2

External References

Related Security Bulletins