Improper Authentication in IBM WebSphere Application Server Liberty - CVE-2020-4421

 

Improper Authentication in IBM WebSphere Application Server Liberty - CVE-2020-4421

Published: September 20, 2023


Vulnerability identifier: #VU80905
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4421
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote user can bypass authentication process and gain unauthorized access to the application.


Affected software

IBM WebSphere Application Server Liberty
Watson Speech to Text, Text to Speech
IBM Cloud Application Business Insights

How to mitigate CVE-2020-4421

Install updates from vendor's website.

Watson Speech to Text, Text to Speech - update to 1.1.2
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2

External References

Related Security Bulletins