PT-2020-18170 · Ibm · Ibm Cloud Pak For Security
Chris Shepherd
+7
·
Published
2020-11-30
·
Updated
2020-11-30
·
CVE-2020-4624
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Cloud Pak for Security version 1.3.0.1 (CP4S)
Description
The issue is related to the use of weaker than expected cryptographic algorithms during negotiation, which could allow an attacker to decrypt sensitive information.
Recommendations
For IBM Cloud Pak for Security version 1.3.0.1 (CP4S), consider updating to a version that uses stronger cryptographic algorithms to prevent decryption of sensitive information by an attacker.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Cloud Pak For Security