CVE-2020-4528

Severity
5.5MEDIUM
EPSS
0.0%
top 85.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 6
Latest updateMay 24

Description

IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information from log files. IBM X-Force ID: 182658.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/datapower_gateway2018.4.1.02018.4.1.12+1
CVEListV5ibm/datapower_gateway10.0.0.0, 2018.4.1.0, 2018.4.1.12+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wgch-rpff-v324: IBM MQ Appliance (IBM DataPower Gateway 102022-05-24
CVEList
CVE-2020-4528: IBM MQ Appliance (IBM DataPower Gateway 102020-10-06
CVE-2020-4528 (MEDIUM CVSS 5.5) | IBM MQ Appliance (IBM DataPower Gat | cvebase.io