First published: Wed May 06 2020(Updated: )
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | >=19.0.0.5<20.0.0.5 | |
<=8.1.4 | ||
<=8.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4421 is medium with a CVSS score of 5.4.
An authenticated user can exploit CVE-2020-4421 by using openidconnect to spoof another user's identity.
IBM Cloud APM Base Private 8.1.4, IBM Cloud APM Advanced Private 8.1.4, and IBM WebSphere Application Server version 19.0.0.5 through 20.0.0.4 are affected by CVE-2020-4421.
For more information about CVE-2020-4421, you can refer to the following links: [IBM X-Force ID: 180084](https://exchange.xforce.ibmcloud.com/vulnerabilities/180084), [IBM support page](https://www.ibm.com/support/pages/node/6205926), [IBM support page](https://www.ibm.com/support/pages/node/6417137).
The Common Weakness Enumeration (CWE) ID for CVE-2020-4421 is 290.