First published: Mon Jul 20 2020(Updated: )
Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Marketing Operations | >=10.1<=10.1.0.3 | |
IBM Marketing Operations | >=11.1.0.1<=11.1.0.2 | |
IBM Marketing Operations | =9.1.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4125 is considered high due to its potential for confidential information disclosure.
To fix CVE-2020-4125, upgrade to the latest patched version of HCL Marketing Operations that addresses the vulnerability.
CVE-2020-4125 affects IBM Marketing Operations versions 9.1.2.4, 10.1.x up to 10.1.0.3, and 11.1.0.x up to 11.1.0.2.
Yes, CVE-2020-4125 can be exploited remotely by a malicious attacker to download sensitive files.
CVE-2020-4125 could expose confidential information stored within the HCL Marketing Operations environment.