PT-2021-12121 · Ibm · Ibm Security Guardium

Chris Shepherd

+7

·

Published

2021-01-27

·

Updated

2021-01-30

·

CVE-2020-4189

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM Security Guardium version 11.2
Description: The issue discloses sensitive information in the response headers, which could be used in further attacks against the system.
Recommendations: For IBM Security Guardium version 11.2, consider restricting access to sensitive information in response headers until a patch is available. As a temporary workaround, review and modify the system's configuration to minimize the disclosure of sensitive information in response headers.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4189

Affected Products

Ibm Security Guardium