CVE-2020-4732
https://notcve.org/view.php?id=CVE-2020-4732
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126. Los productos IBM Jazz Foundation e IBM Engineering, podrían permitir a un usuario autenticado obtener información confidencial debido a una falta de restricciones de seguridad. IBM X-Force ID: 188126 • https://exchange.xforce.ibmcloud.com/vulnerabilities/188126 https://www.ibm.com/support/pages/node/6457739 •
CVE-2020-4495
https://notcve.org/view.php?id=CVE-2020-4495
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114. Los productos IBM Jazz Foundation e IBM Engineering podrían permitir a un atacante remoto omitir las restricciones de seguridad, causadas por un control de acceso inapropiado. Al enviar una petición especialmente diseñada a la API REST, un atacante podría explotar esta vulnerabilidad para omitir las restricciones de acceso y ejecutar acciones arbitrarias con privilegios administrativos. • https://exchange.xforce.ibmcloud.com/vulnerabilities/182114 https://www.ibm.com/support/pages/node/6457739 •