PT-2020-11001 · Ibm · Ibm Security Secret Server

Published

2020-01-28

·

Updated

2020-01-30

·

CVE-2019-4637

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Secret Server version 10.7
Description The issue is related to incomplete blacklisting for input validation, allowing attackers to bypass application controls. This results in a direct impact to the system and data integrity.
Recommendations For IBM Security Secret Server version 10.7, consider implementing additional validation mechanisms to prevent attackers from bypassing application controls until a patch is available. As a temporary workaround, review and enhance the existing blacklisting rules to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-4637

Affected Products

Ibm Security Secret Server