CVE-2020-4964: Medium severity IBM Collaborative Lifecycle Management vulnerability
IBM Jazz Foundation contains an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users.
Other sources
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4964?
The severity of CVE-2020-4964 is currently undisclosed, but it poses a risk of phishing through custom messages.
How do I fix CVE-2020-4964?
To fix CVE-2020-4964, apply the latest security updates provided by IBM for the affected products.
Which IBM products are affected by CVE-2020-4964?
CVE-2020-4964 affects various IBM products including RDNG, DOORS Next, RQM, ETM, among others, up to specified versions.
Can CVE-2020-4964 be exploited by unauthenticated users?
No, CVE-2020-4964 can only be exploited by authenticated users of the affected IBM applications.
Is there a workaround for CVE-2020-4964?
Currently, there is no specific workaround available for CVE-2020-4964, so applying patches is the recommended action.