CVE-2020-4912: High severity ibm cloud pak system vulnerability
IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user. IBM X-Force ID: 191287.
Other sources
IBM Cloud Pak System Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4912?
CVE-2020-4912 is a vulnerability in IBM Cloud Pak System 2.3 Self Service Console that allows a privilege escalation by capturing the user request URL.
How can an attacker exploit CVE-2020-4912?
An attacker can exploit CVE-2020-4912 by capturing the user request URL when logged in as a privileged user.
What is the severity of CVE-2020-4912?
CVE-2020-4912 has a severity rating of 7.2 (high).
Which version of IBM Cloud Pak System is affected by CVE-2020-4912?
IBM Cloud Pak System version 2.3 is affected by CVE-2020-4912.
How can I mitigate the vulnerability in IBM Cloud Pak System?
To mitigate the vulnerability, IBM recommends updating to a version of Cloud Pak System that is not affected by CVE-2020-4912.