9
CVE-2020-4495
- EPSS 2.65%
- Veröffentlicht 02.06.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:32:48
- Erkennungen
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Collaborative Lifecycle Management Version 6.0.6
Ibm ≫ Collaborative Lifecycle Management Version 6.0.6.1
Ibm ≫ Engineering Lifecycle Management Version 7.0
Ibm ≫ Engineering Lifecycle Management Version 7.0.1
Ibm ≫ Engineering Lifecycle Management Version 7.0.2
Ibm ≫ Engineering Lifecycle Optimization - Engineering Insights Version 7.0
Ibm ≫ Engineering Lifecycle Optimization - Engineering Insights Version 7.0.1
Ibm ≫ Engineering Lifecycle Optimization - Engineering Insights Version 7.0.2
Ibm ≫ Engineering Lifecycle Optimization - Publishing Version 7.0
Ibm ≫ Engineering Lifecycle Optimization - Publishing Version 7.0.1
Ibm ≫ Engineering Lifecycle Optimization - Publishing Version 7.0.2
Ibm ≫ Engineering Test Management Version 7.0.0
Ibm ≫ Engineering Test Management Version 7.0.1
Ibm ≫ Rational Doors Next Generation Version 6.0.6
Ibm ≫ Rational Doors Next Generation Version 6.0.6.1
Ibm ≫ Rational Doors Next Generation Version 7.0
Ibm ≫ Rational Doors Next Generation Version 7.0.1
Ibm ≫ Rational Doors Next Generation Version 7.0.2
Ibm ≫ Rational Engineering Lifecycle Manager Version 6.0.6
Ibm ≫ Rational Engineering Lifecycle Manager Version 6.0.6.1
Ibm ≫ Rational Quality Manager Version 6.0.6
Ibm ≫ Rational Quality Manager Version 6.0.6.1
Ibm ≫ Removable Media Manager Version 6.0.6
Ibm ≫ Removable Media Manager Version 6.0.6.1
Ibm ≫ Removable Media Manager Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.65% | 0.836 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
| IBM | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://exchange.xforce.ibmcloud.com/vulnerabilities/182114
https://www.ibm.com/support/pages/node/6457739