Security Bypass Vulnerability in IBM Tivoli Netcool Impact
CVE-2020-4849

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
15 December 2020

Summary

IBM Tivoli Netcool Impact versions ranging from 7.1.0.0 to 7.1.0.19 Interim Fix 7 are susceptible to a security bypass vulnerability. This flaw, stemming from reverse tabnabbing, could enable a remote attacker to exploit the software and redirect a victim to potentially harmful phishing sites, putting sensitive information at risk. Users should ensure they have the latest updates to mitigate this threat. For more information, refer to IBM's support page and X-Force ID: 190294.

Affected Version(s)

Tivoli Netcool Impact 7.1.0

Tivoli Netcool Impact 7.1.0.19.InterimFix.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.