Lucene search

K
cvelistIbmCVELIST:CVE-2020-4794
HistoryDec 21, 2020 - 5:50 p.m.

CVE-2020-4794

2020-12-2117:50:30
ibm
www.cve.org
4
ibm automation workstream services
business automation workflow
business process manager
improper authorization checking
authenticated user
sensitive information
denial of service
ibm x-force id

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

24.8%

IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.

CNA Affected

[
  {
    "product": "Automation Workstream Services",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "19.0.3"
      },
      {
        "status": "affected",
        "version": "20.0.1"
      },
      {
        "status": "affected",
        "version": "20.0.2"
      }
    ]
  },
  {
    "product": "Business Process Manager",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "8.6"
      }
    ]
  },
  {
    "product": "Business Automation Workflow",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "19.0"
      },
      {
        "status": "affected",
        "version": "20.0"
      },
      {
        "status": "affected",
        "version": "18.0"
      }
    ]
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

24.8%

Related for CVELIST:CVE-2020-4794