8.1
CVE-2020-4125
- EPSS 0.13%
- Published 20.07.2020 22:15:11
- Last modified 21.11.2024 05:32:17
- Source psirt@hcl.com
- Teams watchlist Login
- Open Login
Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Marketing Operations Version >= 10.1 <= 10.1.0.3
Ibm ≫ Marketing Operations Version >= 11.1.0.1 <= 11.1.0.2
Ibm ≫ Marketing Operations Version9.1.2.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.297 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
CWE-494 Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.