PT-2020-18100 · Ibm · Ibm Spectrum Protect For Space Management+1
Published
2020-06-15
·
Updated
2021-07-21
·
CVE-2020-4494
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Client versions 8.1.7.0 through 8.1.9.1
IBM Spectrum Protect for Space Management versions 8.1.7.0 through 8.1.9.1
Description
The issue is related to improper session validation in the web user interfaces, which could allow an attacker to bypass authentication and access unauthorized resources.
Recommendations
For IBM Spectrum Protect Client versions 8.1.7.0 through 8.1.9.1, update to a version that includes proper session validation.
For IBM Spectrum Protect for Space Management versions 8.1.7.0 through 8.1.9.1, update to a version that includes proper session validation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect Client
Ibm Spectrum Protect For Space Management