PT-2020-18091 · Ibm · Ibm Urbancode Deploy
Published
2020-11-06
·
Updated
2022-07-12
·
CVE-2020-4482
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM UrbanCode Deploy versions 6.2.7.3 through 6.2.7.4
IBM UrbanCode Deploy versions 7.0.3.0 through 7.0.4.0
Description
The issue allows an authenticated user to bypass security. A user with access to a snapshot could apply unauthorized additional statuses via direct rest calls.
Recommendations
For versions 6.2.7.3 and 6.2.7.4, consider restricting access to direct rest calls until a patch is available.
For versions 7.0.3.0 and 7.0.4.0, consider restricting access to direct rest calls until a patch is available.
As a temporary workaround, consider disabling direct rest calls to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Urbancode Deploy