CVE-2020-4964

3 documents3 sources
Severity
4.3MEDIUM
EPSS
0.2%
top 63.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateMay 24

Description

IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages21 packages

CVEListV5ibm/rational_team_concert6.0.2, 6.0.6, 6.0.6.1+2
NVDibm/rational_team_concert6.0.2, 6.0.6, 6.0.6.1+2
NVDibm/doors_next7.0.0, 7.0.1, 7.0.2+2
NVDibm/engineering_insights7.0.0, 7.0.1, 7.0.2+2
NVDibm/rhapsody_model_manager6.0.2, 6.0.6, 6.0.6.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p758-wxmr-xh9f: IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the appli2022-05-24
CVEList
CVE-2020-4964: IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the appli2021-04-12
CVE-2020-4964 (MEDIUM CVSS 4.3) | IBM Jazz Team Server products conta | cvebase.io