7.2

CVE-2020-4685

A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the application is installed, can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller. IBM X-Force ID: 186625.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cognos Controller Version 10.3.0
Ibm ≫ Cognos Controller Version 10.3.1
Ibm ≫ Cognos Controller Version 10.4.0
Ibm ≫ Cognos Controller Version 10.4.1
Ibm ≫ Cognos Controller Version 10.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.45% 0.707
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
IBM 8 1.3 6
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://exchange.xforce.ibmcloud.com/vulnerabilities/186625
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/6339995
Patch
Vendor Advisory