Use of a broken or risky cryptographic algorithm in S3 Crypto SDK - CVE-2020-8912
Published: September 20, 2023
Vulnerability identifier: #VU80917
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8912
CWE-ID: CWE-327
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A local user can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-CTR.
Affected software
S3 Crypto SDK
IBM Cloud Pak for Watson AIOps
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
How to mitigate CVE-2020-8912
Install updates from vendor's website.
S3 Crypto SDK - update to 2
Netcool Operations Insight - update to 1.6.7
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
Netcool Operations Insight - update to 1.6.7
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4