« Volver al listado

CVE-2020-4125

Estado: ModificadaAlta (8.1)—

Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-4125",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@hcl.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "\"HCL Marketing Operations\"",
          "versions": [
            {
              "status": "affected",
              "version": "\"9.1.2.4, 10.1.x, 11.1.0.x\""
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-07-20T22:15:11.907",
  "references": [
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080941",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@hcl.com"
    },
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080941",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-494"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information."
    },
    {
      "lang": "es",
      "value": "Usando HCL Marketing Operations versiones 9.1.2.4, 10.1.x, 11.1.0.x, un atacante malicioso podría descargar archivos desde el entorno RHEL al hacer  alguna modificación en el enlace, dándole acceso al atacante a información confidencial"
    }
  ],
  "lastModified": "2026-06-17T03:19:33.700",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:marketing_operations:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FAA8655-5455-48BB-A49F-CA6EC1BE05DC",
              "versionEndIncluding": "10.1.0.3",
              "versionStartIncluding": "10.1"
            },
            {
              "criteria": "cpe:2.3:a:ibm:marketing_operations:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34C94E81-6269-4A32-AD6B-4E659C1C5130",
              "versionEndIncluding": "11.1.0.2",
              "versionStartIncluding": "11.1.0.1"
            },
            {
              "criteria": "cpe:2.3:a:ibm:marketing_operations:9.1.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A70F5BA-22A6-47A3-89EA-91182624A85B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@hcl.com"
}