First published: Mon Dec 14 2020(Updated: )
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 190294.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Netcool/Impact | >=7.1.0.0<=7.1.0.19 | |
IBM Tivoli Netcool/Impact | <=7.1.0.0~7.1.0.19 Interim Fix 7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4849 has been categorized with a high severity level due to its potential for exploitation by remote attackers.
To mitigate CVE-2020-4849, ensure that you update IBM Tivoli Netcool Impact to version 7.1.0.20 or later.
CVE-2020-4849 can be exploited to perform phishing attacks by redirecting victims to malicious sites.
CVE-2020-4849 affects IBM Tivoli Netcool Impact versions from 7.1.0.0 to 7.1.0.19 Interim Fix 7.
Currently, the recommended solution for CVE-2020-4849 is to apply the necessary update to resolve the vulnerability.