Vulnerability Description
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Vios | 3.1.0 |
| Ibm | Aix | 7.1.0 |
| Ibm | Power9 | - |
| Fedoraproject | Fedora | 32 |
| Oracle | Communications Cloud Native Core Binding Support Function | 22.1.3 |
| Oracle | Communications Cloud Native Core Network Exposure Function | 22.1.1 |
| Oracle | Communications Cloud Native Core Policy | 22.2.0 |
References
- http://www.openwall.com/lists/oss-security/2020/11/20/3Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/11/23/1Mailing ListThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/189296VDB EntryVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.ibm.com/support/pages/node/6370729PatchVendor Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/11/20/3Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/11/23/1Mailing ListThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/189296VDB EntryVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.ibm.com/support/pages/node/6370729PatchVendor Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
FAQ
What is CVE-2020-4788?
CVE-2020-4788 is a vulnerability with a CVSS score of 4.7 (MEDIUM). IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
How severe is CVE-2020-4788?
CVE-2020-4788 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-4788?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Vios, Ibm Aix, Ibm Power9, Fedoraproject Fedora, Oracle Communications Cloud Native Core Binding Support Function.