← back
CVE-2020-4778

CVE-2020-4778

CVSS 5.9 MEDIUMEPSS 0.8%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Oct 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 cryptographic algorithm used throughout the Cúram application. IBM X-Force ID: 189156.
CVSS:3.0/I:N/AC:H/UI:N/S:U/C:H/PR:N/AV:N/A:N/E:U/RL:O/RC:C
Affected products
IBM · Curam SPM