Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-4606

EPSS 0.04% · P12
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-4606

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 184883.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM Security Verify Privilege Manager 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM Security Verify Privilege Manager是美国IBM公司的一个用于公司环境中用于端点特权管理和应用程序控制的安全管理软件。该软件通过从端点移除本地管理权限,阻止恶意软件和勒索软件的无意下载进而攻击应用程序,利用 IBM Security Privilege Manager,可立即轻松执行最小特权和应用程序控制。。 IBM Security Verify Privilege Manager 10.8 存在安全漏洞,该漏洞源于处理XML数据时容易受到XML外部实体注入(XXE
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
IBMSecurity Verify Privilege Manager 10.8 -

II. Public POCs for CVE-2020-4606

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-4606

登录查看更多情报信息。

Same Patch Batch · IBM · 2021-01-08 · 16 CVEs total

CVE-2020-4697IBM Jazz Foundation 跨站脚本漏洞
CVE-2020-4733IBM Jazz Foundation products 跨站脚本漏洞
CVE-2020-4691IBM Jazz Foundation 跨站脚本漏洞
CVE-2020-4544IBM Jazz Foundation 安全漏洞
CVE-2020-4487IBM Jazz Foundation 信息泄露漏洞
CVE-2020-5021IBM Spectrum Protect Plus 授权问题漏洞
CVE-2020-5022IBM Spectrum Protect Plus 信息泄露漏洞
CVE-2020-5020IBM Spectrum Protect Plus 安全漏洞
CVE-2020-5018IBM Spectrum Protect Plus 信息泄露漏洞
CVE-2020-5019IBM Spectrum Protect和IBM Spectrum Protect Plus 注入漏洞
CVE-2020-5017IBM Spectrum Protect,IBM Spectrum Protect Plus 安全漏洞
CVE-2020-4667IBM Engineering Requirements Quality Assistant 输入验证错误漏洞
CVE-2020-4666IBM Engineering Requirements Quality Assistant 跨站脚本漏洞
CVE-2020-4663IBM Engineering Requirements Quality Assistant 跨站脚本漏洞
CVE-2020-4664IBM Engineering Requirements Quality Assistant 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2020-4606

No comments yet


Leave a comment