CVE-2020-4974
published 2021-07-28CVE-2020-4974: IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…
PriorityP335medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.60%
44.8th percentile
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | engineering_lifecycle_optimization | — | — |
| ibm | engineering_lifecycle_optimization | — | — |
| ibm | engineering_lifecycle_optimization | — | — |
| ibm | engineering_lifecycle_optimization_engineering_insights | — | — |
| ibm | engineering_lifecycle_optimization_engineering_insights | — | — |
| ibm | engineering_lifecycle_optimization_engineering_insights | — | — |
| ibm | engineering_test_management | — | — |
| ibm | engineering_test_management | — | — |
| ibm | engineering_test_management | — | — |
| ibm | engineering_workflow_management | — | — |
| ibm | engineering_workflow_management | — | — |
| ibm | engineering_workflow_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_doors_next_generation | — | — |
| ibm | rational_engineering_lifecycle_manager | — | — |
| ibm | rational_engineering_lifecycle_manager | — | — |
| ibm | rational_engineering_lifecycle_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-16008 chromium-browser: Stack buffer overflow in WebRTC
bugzilla·2020-11-03·CVSS 8.8
CVE-2020-16008 [HIGH] CVE-2020-16008 chromium-browser: Stack buffer overflow in WebRTC
CVE-2020-16008 chromium-browser: Stack buffer overflow in WebRTC
A stack buffer overflow flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1134107
External References:
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1894209]
Affects: fedora-all [bug 1894208]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4974 https://access.redhat.com/errata/RHSA-2020:4974
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-1
Bugzilla
CVE-2020-16005 chromium-browser: Insufficient policy enforcement in ANGLE
bugzilla·2020-11-03·CVSS 8.8
CVE-2020-16005 [HIGH] CVE-2020-16005 chromium-browser: Insufficient policy enforcement in ANGLE
CVE-2020-16005 chromium-browser: Insufficient policy enforcement in ANGLE
An insufficient policy enforcement flaw was found in the ANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1139398
External References:
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1894209]
Affects: fedora-all [bug 1894208]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4974 https://access.redhat.com/errata/RHSA-2020:4974
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/secu
Bugzilla
CVE-2020-16004 chromium-browser: Use after free in user interface
bugzilla·2020-11-03·CVSS 8.8
CVE-2020-16004 [HIGH] CVE-2020-16004 chromium-browser: Use after free in user interface
CVE-2020-16004 chromium-browser: Use after free in user interface
An use after free flaw was found in the user interface component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1138911
External References:
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1894209]
Affects: fedora-all [bug 1894208]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4974 https://access.redhat.com/errata/RHSA-2020:4974
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-202
Bugzilla
CVE-2020-16009 chromium-browser: Inappropriate implementation in V8
bugzilla·2020-11-03·CVSS 8.8
CVE-2020-16009 [HIGH] CVE-2020-16009 chromium-browser: Inappropriate implementation in V8
CVE-2020-16009 chromium-browser: Inappropriate implementation in V8
An inappropriate implementation flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1143772
External References:
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1894209]
Affects: fedora-all [bug 1894208]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4974 https://access.redhat.com/errata/RHSA-2020:4974
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve
Bugzilla
CVE-2020-16006 chromium-browser: Inappropriate implementation in V8
bugzilla·2020-11-03·CVSS 8.8
CVE-2020-16006 [HIGH] CVE-2020-16006 chromium-browser: Inappropriate implementation in V8
CVE-2020-16006 chromium-browser: Inappropriate implementation in V8
An inappropriate implementation flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1133527
External References:
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1894209]
Affects: fedora-all [bug 1894208]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4974 https://access.redhat.com/errata/RHSA-2020:4974
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve
2021-07-28
Published