First published: Fri Apr 09 2021(Updated: )
IBM Jazz Foundation contains an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Collaborative Lifecycle Management | =6.0.2 | |
IBM Collaborative Lifecycle Management | =6.0.6 | |
IBM Collaborative Lifecycle Management | =6.0.6.1 | |
IBM Rational DOORS Next Generation | =7.0.0 | |
IBM Rational DOORS Next Generation | =7.0.1 | |
IBM Rational DOORS Next Generation | =7.0.2 | |
IBM Engineering Insights | =7.0.0 | |
IBM Engineering Insights | =7.0.1 | |
IBM Engineering Insights | =7.0.2 | |
IBM Engineering Lifecycle Manager | =7.0.0 | |
IBM Engineering Lifecycle Manager | =7.0.1 | |
IBM Engineering Lifecycle Manager | =7.0.2 | |
IBM DOORS Next Generation | =6.0.2 | |
IBM DOORS Next Generation | =6.0.6 | |
IBM DOORS Next Generation | =6.0.6.1 | |
IBM Engineering Test Management (ETM) | =7.0.0 | |
IBM Engineering Test Management (ETM) | =7.0.1 | |
IBM Engineering Test Management (ETM) | =7.0.2 | |
IBM Engineering Workflow Management (EWM) | =7.0.0 | |
IBM Engineering Workflow Management (EWM) | =7.0.1 | |
IBM Engineering Workflow Management (EWM) | =7.0.2 | |
IBM Engineering Lifecycle Manager | =6.0.2 | |
IBM Engineering Lifecycle Manager | =6.0.6 | |
IBM Engineering Lifecycle Manager | =6.0.6.1 | |
IBM Rational Quality Manager | =6.0.2 | |
IBM Rational Quality Manager | =6.0.6 | |
IBM Rational Quality Manager | =6.0.6.1 | |
IBM Rational Team Concert | =6.0.2 | |
IBM Rational Team Concert | =6.0.6 | |
IBM Rational Team Concert | =6.0.6.1 | |
IBM Removable Media Manager | =6.0.2 | |
IBM Removable Media Manager | =6.0.6 | |
IBM Removable Media Manager | =6.0.6.1 | |
IBM Removable Media Manager | =7.0.0 | |
IBM Removable Media Manager | =7.0.1 | |
IBM Rhapsody Model Manager | =6.0.2 | |
IBM Rhapsody Model Manager | =6.0.6 | |
IBM Rhapsody Model Manager | =6.0.6.1 | |
IBM Rational DOORS Next Generation | <=6.0.2 | |
IBM Rational DOORS Next Generation | <=7.0.2 | |
IBM Rational DOORS Next Generation | <=7.0 | |
IBM Rational DOORS Next Generation | <=7.0.1 | |
IBM Rational DOORS Next Generation | <=6.0.6.1 | |
IBM Rational DOORS Next Generation | <=6.0.6 | |
IBM Rational Quality Manager (RQM) | <=6.0.6.1 | |
IBM Engineering Test Management (ETM) | <=7.0.1 | |
IBM Rational Quality Manager (RQM) | <=6.0.6 | |
IBM Engineering Test Management (ETM) | <=7.0.0 | |
IBM Rational Quality Manager (RQM) | <=6.0.2 | |
IBM Engineering Test Management (ETM) | <=7.0.2 | |
IBM Removable Media Manager | <=7.0.1 | |
IBM Rhapsody Model Manager | <=6.0.6 | |
IBM Removable Media Manager | <=6.0.6.1 | |
IBM Rhapsody Model Manager | <=6.0.2 | |
IBM Removable Media Manager | <=6.0.6 | |
IBM Rhapsody Model Manager | <=6.0.6.1 | |
IBM Removable Media Manager | <=7.0 | |
IBM Removable Media Manager | <=6.0.2 | |
IBM Engineering Workflow Management (EWM) | <=7.0.1 | |
IBM Rational Team Concert | <=6.0.2 | |
IBM Rational Team Concert | <=6.0.6.1 | |
IBM Engineering Workflow Management (EWM) | <=7.0 | |
IBM Rational Team Concert | <=6.0.6 | |
IBM Engineering Workflow Management (EWM) | <=7.0.2 | |
IBM Engineering Lifecycle Management | <=6.0.6.1 | |
IBM Engineering Lifecycle Management | <=6.0.6 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0 | |
IBM Engineering Lifecycle Management | <=6.0.2 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0.1 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0.2 | |
IBM Engineering Lifecycle Management (ELM) | <=6.0.6.1 | |
IBM ENI | <=7.0.1 | |
IBM Engineering Lifecycle Management (ELM) | <=6.0.6 | |
IBM ENI | <=7.0 | |
IBM Engineering Lifecycle Management (ELM) | <=6.0.2 | |
IBM ENI | <=7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4964 is currently undisclosed, but it poses a risk of phishing through custom messages.
To fix CVE-2020-4964, apply the latest security updates provided by IBM for the affected products.
CVE-2020-4964 affects various IBM products including RDNG, DOORS Next, RQM, ETM, among others, up to specified versions.
No, CVE-2020-4964 can only be exploited by authenticated users of the affected IBM applications.
Currently, there is no specific workaround available for CVE-2020-4964, so applying patches is the recommended action.