PT-2020-18084 · Ibm · Ibm Spectrum Protect Plus
Published
2020-06-15
·
Updated
2020-06-17
·
CVE-2020-4469
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5
Description
The issue allows a remote attacker to execute arbitrary code on the system by using a specially crafted HTTP command. This enables the attacker to execute arbitrary commands on the system. The problem stems from an incomplete fix for a previous issue.
Recommendations
For IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5, consider restricting access to the system until a complete fix is applied to prevent exploitation. As a temporary workaround, limit the use of HTTP commands to minimize the risk of arbitrary code execution.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect Plus