Lucene search

K
ibmIBM25CD6FE340F22514220FD6473DC911FECCFC9E40EE608FECC7A422AEEE34ECB9
HistoryAug 06, 2020 - 5:16 p.m.

Security Bulletin: Content Collector for Email is affected by a embedded WebSphere Application Server is vulnerable to a privilege escalation vulnerability

2020-08-0617:16:24
www.ibm.com
10

EPSS

0.001

Percentile

39.9%

Summary

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.

Vulnerability Details

CVEID:CVE-2020-4362
**DESCRIPTION:**IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/178929 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Content Collector for Email 4.0.0, 4.0.1

Remediation/Fixes

Product VRM Remediation
Content Collector for Email 4.0.0, 4.0.1 Use Content Collector for Email 4.0.1.9 Interim Fix IF006

Workarounds and Mitigations

None

EPSS

0.001

Percentile

39.9%

Related for 25CD6FE340F22514220FD6473DC911FECCFC9E40EE608FECC7A422AEEE34ECB9