CVE-2020-4821
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
16/07/2021
Last modified:
29/07/2021
Description
IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:ibm:infosphere_data_replication:11.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:infosphere_data_replication:11.4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:infosphere_change_data_capture:10.2.1:*:*:*:*:z\/os:*:* | ||
cpe:2.3:a:ibm:infosphere_change_data_capture:11.3.3:*:*:*:*:z\/os:*:* | ||
cpe:2.3:a:ibm:infosphere_change_data_capture:11.4:*:*:*:*:z\/os:*:* |
To consult the complete list of CPE names with products and versions, see this page