CVE-2020-4495
published 2021-06-02CVE-2020-4495: IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a…
high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | collaborative_lifecycle_management | — | — |
| ibm | collaborative_lifecycle_management | — | — |
| ibm | engineering_lifecycle_management | — | — |
| ibm | engineering_lifecycle_management | — | — |
| ibm | engineering_lifecycle_management | — | — |
| ibm | engineering_lifecycle_optimization | — | — |
| ibm | engineering_lifecycle_optimization | — | — |
| ibm | engineering_lifecycle_optimization | — | — |
| ibm | engineering_lifecycle_optimization_engineering_insights | — | — |
| ibm | engineering_lifecycle_optimization_engineering_insights | — | — |
| ibm | engineering_lifecycle_optimization_engineering_insights | — | — |
| ibm | engineering_lifecycle_optimization_publishing | — | — |
| ibm | engineering_lifecycle_optimization_publishing | — | — |
| ibm | engineering_lifecycle_optimization_publishing | — | — |
| ibm | engineering_test_management | — | — |
| ibm | engineering_test_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_engineering_lifecycle_manager | — | — |
| ibm | rational_engineering_lifecycle_manager | — | — |