CVE Vulnerabilities

CVE-2020-4499

Published: Oct 15, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.

Affected Software

NameVendorStart VersionEnd Version
Security_access_managerIbm9.0.7.0 (including)9.0.7.2 (excluding)
Security_verify_accessIbm10.0.0 (including)10.0.0.1 (excluding)

References