First published: Mon Dec 14 2020(Updated: )
IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connect | =direct-4.2.0 | |
IBM Connect | =direct-4.3.0 | |
IBM Connect | =direct-6.0.0 | |
IBM Connect | =direct-6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4747 is classified as high due to the potential for unauthorized access to CLI sessions.
To fix CVE-2020-4747, you should apply the latest security patches provided by IBM for affected versions of Connect:Direct.
CVE-2020-4747 affects local or remote users of IBM Connect:Direct for UNIX versions 4.2.0, 4.3.0, 6.0.0, and 6.1.0.
Attackers can obtain an authenticated CLI session, which may allow them to perform unauthorized actions within the system.
CVE-2020-4747 is considered an authenticated vulnerability, as it requires a user account to exploit.