CVE-2020-4208
published 2020-03-31CVE-2020-4208: IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.75%
75.4th percentile
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| ibm | spectrum_protect_plus | — | — |
| ibm | spectrum_protect_plus | — | — |
| ibm | spectrum_protect_plus | 10.1.0 – 10.1.5 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ww5p-8f54-rr8x: IBM Spectrum Protect Plus 10
ghsa_unreviewed·2022-05-24
CVE-2020-4208 [HIGH] GHSA-ww5p-8f54-rr8x: IBM Spectrum Protect Plus 10
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.
Apache
Apache nifi: CVE-2020-1942
vendor_apache·CVSS 7.5
CVE-2020-1942 Apache nifi: CVE-2020-1942
Apache nifi: CVE-2020-1942
Title: Potential Information Disclosure in Application Logs Published: 2020-02-04 Severity: Medium Products: Apache NiFi Affected Versions: 0.0.1 to 1.11.0 Fixed Versions: 1.11.1 Reporter: Andy LoPresto References CVE Record: CVE-2020-1942 NVD Record: CVE-2020-1942 Apache Jira Issue: NIFI-7079 GitHub Pull Request: 4208 The flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext. NiFi 1.11.1i implemented Argon2 secure hashing to provide a deterministic loggable value which does not reveal the sensitive valu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-31
Published