CVE-2020-4685
Summary
| CVE | CVE-2020-4685 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-11 13:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the application is installed, can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller. IBM X-Force ID: 186625. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Cognos Controller | 10.3.0 | All | All | All |
| Application | Ibm | Cognos Controller | 10.3.1 | All | All | All |
| Application | Ibm | Cognos Controller | 10.4.0 | All | All | All |
| Application | Ibm | Cognos Controller | 10.4.1 | All | All | All |
| Application | Ibm | Cognos Controller | 10.4.2 | All | All | All |
| Application | Ibm | Cognos Controller | 10.3.0 | All | All | All |
| Application | Ibm | Cognos Controller | 10.3.1 | All | All | All |
| Application | Ibm | Cognos Controller | 10.4.0 | All | All | All |
| Application | Ibm | Cognos Controller | 10.4.1 | All | All | All |
| Application | Ibm | Cognos Controller | 10.4.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: IBM Cognos Controller is vulnerable to privilege escalation (CVE-2020-4685) | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.