CVE-2020-4125

HIGH

IBM Marketing Operations < 10.1.0.3 - Download Without Integrity Check

Title source: rule
STIX 2.1

Description

Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.

Scores

CVSS v3 8.1
EPSS 0.0013
EPSS Percentile 32.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-494
Status published
Products (2)
ibm/marketing_operations 9.1.2.4
ibm/marketing_operations 10.1 - 10.1.0.3
Published Jul 20, 2020
Tracked Since Feb 18, 2026