CVE-2020-4495
CVE-2020-4495
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 2.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
02 Jun 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.
CVSS:3.0/AV:N/PR:L/I:H/AC:L/A:H/UI:N/S:U/C:H/E:U/RL:O/RC:C
Affected products
IBM · Engineering Lifecycle OptimizationIBM · Engineering Test ManagementIBM · Rational Collaborative Lifecycle ManagementIBM · Rational DOORS Next GenerationIBM · Rational Engineering Lifecycle ManagerIBM · Rational Quality ManagerIBM · Rational Rhapsody Model ManagerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →