CVE-2020-4719
Summary
| CVE | CVE-2020-4719 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-02 17:15:00 UTC |
| Updated | 2021-03-09 13:55:00 UTC |
| Description | The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM X-Force ID: 187861. |
Risk And Classification
Problem Types: CWE-706
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Cloud Application Performance Management | 8.1.4 | All | All | All |
| Application | Ibm | Cloud Application Performance Management | 8.1.4 | All | All | All |
| Application | Ibm | Cloud Application Performance Management | 8.1.4 | All | All | All |
| Application | Ibm | Cloud Application Performance Management | 8.1.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Multiple vulnerabilities affect the IBM Performance Management product | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.