PT-2020-18061 · Ibm · Websphere Application Liberty

Published

2020-05-06

·

Updated

2021-07-21

·

CVE-2020-4421

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Liberty versions 19.0.0.5 through 20.0.0.4
Description The issue allows an authenticated user using openidconnect to spoof another user's identity.
Recommendations For versions 19.0.0.5 through 20.0.0.4, consider disabling the openidconnect feature until a patch is available to prevent user identity spoofing.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4421

Affected Products

Websphere Application Liberty