Lucene search

K
ibmIBMAB595BAD745ACCEB2CA1F5A7FC0DC9717FFDD74D2EEC460390003F7C91DD4FFD
HistoryMay 14, 2021 - 9:20 p.m.

Security Bulletin: Eclipse Jetty Vulnerability Affects IBM Control Center (CVE-2020-27216)

2021-05-1421:20:10
www.ibm.com
10

0.001 Low

EPSS

Percentile

31.0%

Summary

Eclipse Jetty could allow a local authenticated attacker to gain elevated privileges on the system.

Vulnerability Details

CVEID:CVE-2020-27216
**DESCRIPTION:**Eclipse Jetty could allow a local authenticated attacker to gain elevated privileges on the system, caused by a race condition in the creation of the temporary subdirectory. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190474 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Control Center 6.2.0.0

Remediation/Fixes

Product |

VRMF

|

iFix

|

Remediation

—|—|—|—

IBM Control Center

|

6.2.0.0

|

iFix08

|

Fix Central - 6.2.0.0

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm control centereq6.2.0.0

0.001 Low

EPSS

Percentile

31.0%