4.9
CVE-2020-4719
- EPSS 0.22%
- Veröffentlicht 02.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:10
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM X-Force ID: 187861.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Application Performance Management Version8.1.4 SwPlatformadvanced_private
Ibm ≫ Cloud Application Performance Management Version8.1.4 SwPlatformbase_private
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.444 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
| psirt@us.ibm.com | 4.9 | 1.2 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
CWE-706 Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.