CVE-2020-4495: Critical severity IBM DOORS Next vulnerability
IBM Engineering Systems Design Rhapsody - Model Manager could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges.
Other sources
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-4495.
What is the severity level of CVE-2020-4495?
The severity level of CVE-2020-4495 is critical.
Which software versions are affected by CVE-2020-4495?
CVE-2020-4495 affects IBM Collaborative Lifecycle Management versions 6.0.6 and 6.0.6.1, IBM Engineering Lifecycle Management versions 7.0, 7.0.1, and 7.0.2, and other related IBM products.
What is the nature of this vulnerability?
CVE-2020-4495 is a security bypass vulnerability that allows a remote attacker to bypass access restrictions and execute arbitrary code.
Where can I find more information about CVE-2020-4495?
More information about CVE-2020-4495 can be found on the IBM X-Force Exchange website and the IBM support pages.