← back
CVE-2020-4719medium

CVE-2020-4719

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.9epss 0.9%
exploitation probability
0.9%top 41% of all CVEs
observed exploitation
nono source reports it
The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM X-Force ID: 187861.
CVSS:3.0/UI:N/PR:H/I:H/AV:N/A:N/S:U/C:N/AC:L/RL:O/RC:C/E:U
Affected products
IBM · Cloud APM