PT-2020-17927 · Ibm · Ibm Storediq
Published
2020-02-03
·
Updated
2021-07-21
·
CVE-2020-4224
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM StoredIQ versions 7.6.0.17 through 7.6.0.20
Description
The issue could disclose sensitive information to a local user due to data in certain directories not being encrypted when it contained symbolic links.
Recommendations
For IBM StoredIQ versions 7.6.0.17 through 7.6.0.20, ensure that data in directories containing symbolic links is properly encrypted to prevent unauthorized access.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Storediq