CVE-2020-4495
02.06.2021, 21:15
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | collaborative_lifecycle_management | 6.0.6 |
ibm | collaborative_lifecycle_management | 6.0.6.1 |
ibm | engineering_lifecycle_management | 7.0 |
ibm | engineering_lifecycle_management | 7.0.1 |
ibm | engineering_lifecycle_management | 7.0.2 |
ibm | engineering_lifecycle_optimization_-_engineering_insights | 7.0 |
ibm | engineering_lifecycle_optimization_-_engineering_insights | 7.0.1 |
ibm | engineering_lifecycle_optimization_-_engineering_insights | 7.0.2 |
ibm | engineering_lifecycle_optimization_-_publishing | 7.0 |
ibm | engineering_lifecycle_optimization_-_publishing | 7.0.1 |
ibm | engineering_lifecycle_optimization_-_publishing | 7.0.2 |
ibm | engineering_test_management | 7.0.0 |
ibm | engineering_test_management | 7.0.1 |
ibm | rational_doors_next_generation | 6.0.6 |
ibm | rational_doors_next_generation | 6.0.6.1 |
ibm | rational_doors_next_generation | 7.0 |
ibm | rational_doors_next_generation | 7.0.1 |
ibm | rational_doors_next_generation | 7.0.2 |
ibm | rational_engineering_lifecycle_manager | 6.0.6 |
ibm | rational_engineering_lifecycle_manager | 6.0.6.1 |
ibm | rational_quality_manager | 6.0.6 |
ibm | rational_quality_manager | 6.0.6.1 |
ibm | removable_media_manager | 6.0.6 |
ibm | removable_media_manager | 6.0.6.1 |
ibm | removable_media_manager | 7.0 |
𝑥
= Vulnerable software versions