CVE-2020-4989

IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an authenticated user to obtain sensitive information about build definitions. IBM X-Force ID: 192707.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:rational_team_concert:6.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_team_concert:6.0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_team_concert:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_team_concert:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_team_concert:7.0.2:*:*:*:*:*:*:*

History

22 Mar 2022, 16:10

Type Values Removed Values Added
First Time Ibm rational Team Concert
Ibm
References (CONFIRM) https://www.ibm.com/support/pages/node/6563261 - (CONFIRM) https://www.ibm.com/support/pages/node/6563261 - Patch, Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/192707 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/192707 - VDB Entry, Vendor Advisory
CWE CWE-668
CPE cpe:2.3:a:ibm:rational_team_concert:6.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_team_concert:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_team_concert:6.0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_team_concert:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_team_concert:7.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3

15 Mar 2022, 18:15

Type Values Removed Values Added
Summary IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an authenticated user to obtain sensitive information about build definitions. IBM X-Force ID: 192707. IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an authenticated user to obtain sensitive information about build definitions. IBM X-Force ID: 192707.

15 Mar 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-15 17:15

Updated : 2023-12-10 14:22


NVD link : CVE-2020-4989

Mitre link : CVE-2020-4989

CVE.ORG link : CVE-2020-4989


JSON object : View

Products Affected

ibm

  • rational_team_concert
CWE
CWE-668

Exposure of Resource to Wrong Sphere