PT-2020-18100 · Ibm · Ibm Spectrum Protect For Space Management+1

Published

2020-06-15

·

Updated

2021-07-21

·

CVE-2020-4494

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Client versions 8.1.7.0 through 8.1.9.1 IBM Spectrum Protect for Space Management versions 8.1.7.0 through 8.1.9.1
Description The issue is related to improper session validation in the web user interfaces, which could allow an attacker to bypass authentication and access unauthorized resources.
Recommendations For IBM Spectrum Protect Client versions 8.1.7.0 through 8.1.9.1, update to a version that includes proper session validation. For IBM Spectrum Protect for Space Management versions 8.1.7.0 through 8.1.9.1, update to a version that includes proper session validation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4494

Affected Products

Ibm Spectrum Protect Client
Ibm Spectrum Protect For Space Management