Vulnerability CVE-2020-4974


Published: 2021-07-28

Description:
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.

Type:

CWE-918

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
IBM -> Engineering lifecycle optimization - engineering insights 
IBM -> Engineering requirements quality assistant on-premises 
IBM -> Engineering test management 
IBM -> Engineering workflow management 
IBM -> Rational collaborative lifecycle management 
IBM -> Rational engineering lifecycle manager 
IBM -> Rational doors next generation 
IBM -> Rational quality manager 
IBM -> Rational team concert 

 References:
https://www.ibm.com/support/pages/node/6475919
https://exchange.xforce.ibmcloud.com/vulnerabilities/192434

Copyright 2024, cxsecurity.com

 

Back to Top