Spoofing attack in IBM Cloud Pak for Business Automation - CVE-2020-4577
Published: May 13, 2025
Vulnerability identifier: #VU109017
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4577
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data. A remote user can persuade a victim to visit a malicious Web site and exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Affected software
IBM Cloud Pak for Business Automation
How to mitigate CVE-2020-4577
Install updates from vendor's website.
IBM Cloud Pak for Business Automation - update to 20.0.2 ifix 001