CVE-2020-4421Authentication Bypass by Spoofing in IBM Websphere Application Server

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 61.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5ibm/websphere_application_server_liberty19.0.0.5, 20.0.0.4+1
NVDibm/websphere_application_server19.0.0.520.0.0.5

🔴Vulnerability Details

2
GHSA
GHSA-c453-37mp-9fx2: IBM WebSphere Application Liberty 192022-05-24
CVEList
CVE-2020-4421: IBM WebSphere Application Liberty 192020-05-06