PT-2021-12121 · Ibm · Ibm Security Guardium
Chris Shepherd
+7
·
Published
2021-01-27
·
Updated
2021-01-30
·
CVE-2020-4189
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Security Guardium version 11.2
Description:
The issue discloses sensitive information in the response headers, which could be used in further attacks against the system.
Recommendations:
For IBM Security Guardium version 11.2, consider restricting access to sensitive information in response headers until a patch is available. As a temporary workaround, review and modify the system's configuration to minimize the disclosure of sensitive information in response headers.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Guardium