8.1
CVE-2020-4125
- EPSS 0.13%
- Veröffentlicht 20.07.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:17
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Marketing Operations Version >= 10.1 <= 10.1.0.3
Ibm ≫ Marketing Operations Version >= 11.1.0.1 <= 11.1.0.2
Ibm ≫ Marketing Operations Version9.1.2.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.297 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
CWE-494 Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.