CVE-2020-4841

MEDIUM WAF: Low
CVSS 5.9 Published: 2020-12-21
CWE-862

IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 190045.

WAF Coverage Analysis

Missing Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
ibmsecurity_secret_server10.6

References

Back to CVE Database