CVE-2020-4421: Medium severity ibm cloud application performance management vulnerability
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
Other sources
IBM WebSphere Application Liberty could allow an authenticated user using openidconnect to spoof another users identify.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4421?
The severity of CVE-2020-4421 is medium with a CVSS score of 5.4.
How can an authenticated user exploit CVE-2020-4421?
An authenticated user can exploit CVE-2020-4421 by using openidconnect to spoof another user's identity.
Which IBM products are affected by CVE-2020-4421?
IBM Cloud APM Base Private 8.1.4, IBM Cloud APM Advanced Private 8.1.4, and IBM WebSphere Application Server version 19.0.0.5 through 20.0.0.4 are affected by CVE-2020-4421.
Where can I find more information about CVE-2020-4421?
For more information about CVE-2020-4421, you can refer to the following links: [IBM X-Force ID: 180084](https://exchange.xforce.ibmcloud.com/vulnerabilities/180084), [IBM support page](https://www.ibm.com/support/pages/node/6205926), [IBM support page](https://www.ibm.com/support/pages/node/6417137).
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-4421?
The Common Weakness Enumeration (CWE) ID for CVE-2020-4421 is 290.