CVE-2020-4233
published 2020-05-28CVE-2020-4233: IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure…
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.77%
51.4th percentile
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 175360.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_identity_governance_and_intelligence | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_17 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_18 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_6 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_7 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78r3-9hh9-vr5w: IBM Security Identity Governance and Intelligence 5
ghsa_unreviewed·2022-05-24
CVE-2020-4233 [MEDIUM] CWE-200 GHSA-78r3-9hh9-vr5w: IBM Security Identity Governance and Intelligence 5
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 175360.
Microsoft
Microsoft Exchange Server Information Disclosure Vulnerability
vendor_msrc·2020-12-08·CVSS 8.8
CVE-2020-17143 [HIGH] Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.
Microsoft Exchange Server: Microsoft Exchange Server
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: http://www.microsoft.com/download/details.aspx?familyid=92703e12-dacb-4233-b6d3-028c3e6cfd1e
Reference: https://support.microsoft.com/help/4593465
Reference: http://www.microsoft.com/download/details.aspx?familyid=32c10d21-2fe9-478
Microsoft
Microsoft Exchange Remote Code Execution Vulnerability
vendor_msrc·2020-12-08·CVSS 6.6
CVE-2020-17117 [MEDIUM] Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Exchange Server: Microsoft Exchange Server
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: http://www.microsoft.com/download/details.aspx?familyid=64b1d61d-63e8-4d41-923d-0f89f1982739
Reference: https://support.microsoft.com/help/4593466
Reference: http://www.microsoft.com/download/details.aspx?familyid=92703e12-dacb-4233-b6d3-028c3e6cfd1e
Reference: https://support.microsoft.com/help/4593465
Reference: http://www.microsoft.com/download/details.aspx?familyid=32c10d21-2fe9-4781-80c3-35edb7211648
Reference: https://www.microsoft
Microsoft
Microsoft Exchange Remote Code Execution Vulnerability
vendor_msrc·2020-12-08·CVSS 8.4
CVE-2020-17141 [HIGH] Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Exchange Remote Code Execution Vulnerability
FAQ: What can cause this vulnerability?
The vulnerability occurs due to improper validation of cmdlet arguments.
Does the attacker need to be in an authenticated role in the Exchange Server?
Yes, the attacker must be authenticated.
Microsoft Exchange Server: Microsoft Exchange Server
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: http://www.microsoft.com/download/details.aspx?familyid=92703e12-dacb-4233-b6d3-028c3e6cfd1e
Reference: https://support.microsoft.com/help/4593465
Reference: http://www.microsoft.com/download/details.aspx?family
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-05-28
Published