{"api_version":"1","generated_at":"2026-07-23T14:10:15+00:00","cve":"CVE-2020-4719","urls":{"html":"https://cve.report/CVE-2020-4719","api":"https://cve.report/api/cve/CVE-2020-4719.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-4719","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-4719"},"summary":{"title":"CVE-2020-4719","description":"The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM X-Force ID: 187861.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2021-03-02 17:15:00","updated_at":"2021-03-09 13:55:00"},"problem_types":["CWE-706"],"metrics":[],"references":[{"url":"https://www.ibm.com/support/pages/node/6417137","name":"https://www.ibm.com/support/pages/node/6417137","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: Multiple vulnerabilities affect the IBM Performance Management product","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/187861","name":"ibm-monitoring-cve20204719-sec-bypass (187861)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-4719","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-4719","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"4719","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cloud_application_performance_management","cpe6":"8.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"advanced_private","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4719","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cloud_application_performance_management","cpe6":"8.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"base_private","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4719","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cloud_application_performance_management","cpe6":"8.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"advanced_private","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4719","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cloud_application_performance_management","cpe6":"8.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"base_private","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2020-4719","STATE":"PUBLIC","ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2021-02-26T00:00:00"},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Bypass Security"}]}]},"data_type":"CVE","description":{"description_data":[{"value":"The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM X-Force ID: 187861.","lang":"eng"}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"product_name":"Cloud APM","version":{"version_data":[{"version_value":"8.1.4"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.ibm.com/support/pages/node/6417137","title":"IBM Security Bulletin 6417137 (Cloud APM)","refsource":"CONFIRM","name":"https://www.ibm.com/support/pages/node/6417137"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/187861","name":"ibm-monitoring-cve20204719-sec-bypass (187861)","title":"X-Force Vulnerability Report","refsource":"XF"}]},"impact":{"cvssv3":{"BM":{"UI":"N","SCORE":"4.900","PR":"H","I":"H","AV":"N","A":"N","S":"U","C":"N","AC":"L"},"TM":{"RL":"O","RC":"C","E":"U"}}},"data_version":"4.0","data_format":"MITRE"},"nvd":{"publishedDate":"2021-03-02 17:15:00","lastModifiedDate":"2021-03-09 13:55:00","problem_types":["CWE-706"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:cloud_application_performance_management:8.1.4:*:*:*:*:advanced_private:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:cloud_application_performance_management:8.1.4:*:*:*:*:base_private:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"4719","Ordinal":"164747","Title":"CVE-2020-4719","CVE":"CVE-2020-4719","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"4719","Ordinal":"1","NoteData":"The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM X-Force ID: 187861.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"4719","Ordinal":"2","NoteData":"2021-03-02","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"4719","Ordinal":"3","NoteData":"2021-03-02","Type":"Other","Title":"Modified"}]}}}