PT-2020-18061 · Ibm · Websphere Application Liberty
Published
2020-05-06
·
Updated
2021-07-21
·
CVE-2020-4421
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Liberty versions 19.0.0.5 through 20.0.0.4
Description
The issue allows an authenticated user using
openidconnect to spoof another user's identity.Recommendations
For versions 19.0.0.5 through 20.0.0.4, consider disabling the
openidconnect feature until a patch is available to prevent user identity spoofing.Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Websphere Application Liberty