CVE-2020-4811: Input Validation
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a privileged user to inject inject malicious data using a specially crafted HTTP request due to improper input validation.
Other sources
IBM Cloud Pak for Security (CP4S) could allow a privileged user to inject inject malicious data using a specially crafted HTTP request due to improper input validation.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4811.
What is the severity of CVE-2020-4811?
The severity of CVE-2020-4811 is medium, with a severity value of 2.4.
Which version of IBM Cloud Pak for Security (CP4S) is affected?
IBM Cloud Pak for Security (CP4S) versions 1.4.0.0 to 1.6.0.1 are affected.
How does the vulnerability in IBM Cloud Pak for Security (CP4S) occur?
The vulnerability in IBM Cloud Pak for Security (CP4S) occurs when a privileged user injects malicious data using a specially crafted HTTP request due to improper input validation.
How can the vulnerability in IBM Cloud Pak for Security (CP4S) be fixed?
To fix the vulnerability in IBM Cloud Pak for Security (CP4S), it is recommended to apply the necessary security patches or updates provided by IBM.