Spoofing attack in IBM Cloud Pak for Business Automation - CVE-2020-4577

 

Spoofing attack in IBM Cloud Pak for Business Automation - CVE-2020-4577

Published: May 13, 2025


Vulnerability identifier: #VU109017
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4577
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data. A remote user can persuade a victim to visit a malicious Web site and exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.


Affected software

IBM Cloud Pak for Business Automation

How to mitigate CVE-2020-4577

Install updates from vendor's website.

IBM Cloud Pak for Business Automation - update to 20.0.2 ifix 001

External References

Related Security Bulletins