CVE Vulnerabilities

CVE-2020-4495

Published: Jun 02, 2021 | Modified: Jul 12, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.

Affected Software

Name Vendor Start Version End Version
Collaborative_lifecycle_management Ibm 6.0.6 (including) 6.0.6 (including)
Collaborative_lifecycle_management Ibm 6.0.6.1 (including) 6.0.6.1 (including)
Engineering_lifecycle_management Ibm 7.0 (including) 7.0 (including)
Engineering_lifecycle_management Ibm 7.0.1 (including) 7.0.1 (including)
Engineering_lifecycle_management Ibm 7.0.2 (including) 7.0.2 (including)
Engineering_lifecycle_optimization_-_engineering_insights Ibm 7.0 (including) 7.0 (including)
Engineering_lifecycle_optimization_-_engineering_insights Ibm 7.0.1 (including) 7.0.1 (including)
Engineering_lifecycle_optimization_-_engineering_insights Ibm 7.0.2 (including) 7.0.2 (including)
Engineering_lifecycle_optimization_-_publishing Ibm 7.0 (including) 7.0 (including)
Engineering_lifecycle_optimization_-_publishing Ibm 7.0.1 (including) 7.0.1 (including)
Engineering_lifecycle_optimization_-_publishing Ibm 7.0.2 (including) 7.0.2 (including)
Engineering_test_management Ibm 7.0.0 (including) 7.0.0 (including)
Engineering_test_management Ibm 7.0.1 (including) 7.0.1 (including)
Rational_doors_next_generation Ibm 6.0.6 (including) 6.0.6 (including)
Rational_doors_next_generation Ibm 6.0.6.1 (including) 6.0.6.1 (including)
Rational_doors_next_generation Ibm 7.0 (including) 7.0 (including)
Rational_doors_next_generation Ibm 7.0.1 (including) 7.0.1 (including)
Rational_doors_next_generation Ibm 7.0.2 (including) 7.0.2 (including)
Rational_engineering_lifecycle_manager Ibm 6.0.6 (including) 6.0.6 (including)
Rational_engineering_lifecycle_manager Ibm 6.0.6.1 (including) 6.0.6.1 (including)
Rational_quality_manager Ibm 6.0.6 (including) 6.0.6 (including)
Rational_quality_manager Ibm 6.0.6.1 (including) 6.0.6.1 (including)
Removable_media_manager Ibm 6.0.6 (including) 6.0.6 (including)
Removable_media_manager Ibm 6.0.6.1 (including) 6.0.6.1 (including)
Removable_media_manager Ibm 7.0 (including) 7.0 (including)

References