PT-2020-18051 · Ibm · Ibm Verify Gateway

Chris Shepherd

+8

·

Published

2020-07-27

·

Updated

2020-07-28

·

CVE-2020-4405

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Verify Gateway (IVG) versions 1.0.0 through 1.0.1
Description The issue could disclose potentially sensitive information to an authenticated user due to world-readable log files.
Recommendations For versions 1.0.0 and 1.0.1, consider restricting access to the log files to prevent unauthorized disclosure of sensitive information. As a temporary workaround, modify the log file permissions to prevent world-readable access until a fix is available.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4405

Affected Products

Ibm Verify Gateway