Improper Authentication in IBM WebSphere Application Server Liberty - CVE-2020-4421
Published: September 20, 2023
Vulnerability identifier: #VU80905
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4421
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote user can bypass authentication process and gain unauthorized access to the application.
Affected software
IBM WebSphere Application Server Liberty
Watson Speech to Text, Text to Speech
IBM Cloud Application Business Insights
Watson Speech to Text, Text to Speech
IBM Cloud Application Business Insights
How to mitigate CVE-2020-4421
Install updates from vendor's website.
Watson Speech to Text, Text to Speech - update to 1.1.2
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2