cvelist/2020/4xxx/CVE-2020-4499.json
2020-10-15 13:01:46 +00:00

100 lines
3.1 KiB
JSON

{
"data_format": "MITRE",
"problemtype": {
"problemtype_data": [
{
"description": [
{
"value": "Bypass Security",
"lang": "eng"
}
]
}
]
},
"description": {
"description_data": [
{
"value": "IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.",
"lang": "eng"
}
]
},
"impact": {
"cvssv3": {
"TM": {
"RC": "C",
"E": "U",
"RL": "O"
},
"BM": {
"I": "L",
"UI": "N",
"SCORE": "7.300",
"AC": "L",
"PR": "N",
"AV": "N",
"C": "L",
"S": "U",
"A": "L"
}
}
},
"CVE_data_meta": {
"DATE_PUBLIC": "2020-10-14T00:00:00",
"STATE": "PUBLIC",
"ASSIGNER": "psirt@us.ibm.com",
"ID": "CVE-2020-4499"
},
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"title": "IBM Security Bulletin 6348046 (Security Access Manager)",
"name": "https://www.ibm.com/support/pages/node/6348046",
"url": "https://www.ibm.com/support/pages/node/6348046"
},
{
"title": "X-Force Vulnerability Report",
"name": "ibm-sam-cve20204499-sec-bypass (182216)",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/182216",
"refsource": "XF"
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Security Verify Access",
"version": {
"version_data": [
{
"version_value": "10.0.0"
}
]
}
},
{
"version": {
"version_data": [
{
"version_value": "9.0.7"
}
]
},
"product_name": "Security Access Manager"
}
]
},
"vendor_name": "IBM"
}
]
}
},
"data_type": "CVE",
"data_version": "4.0"
}