CVE Vulnerabilities

CVE-2020-4499

Published: Oct 15, 2020 | Modified: Jul 21, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.

Affected Software

Name Vendor Start Version End Version
Security_access_manager Ibm 9.0.7.0 (including) 9.0.7.2 (excluding)
Security_verify_access Ibm 10.0.0 (including) 10.0.0.1 (excluding)

References