PT-2020-18216 · Ibm · Ibm Spectrum Protect Plus

Published

2020-09-15

·

Updated

2020-09-16

·

CVE-2020-4711

CVSS v3.1

6.5

Medium

VectorA:N/AC:L/S:U/AV:N/I:N/UI:N/C:H/PR:L
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6
Description The issue allows a remote attacker to traverse directories on the system by sending a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
Recommendations For IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, avoid using URL requests that contain dot dot sequences (/../) to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4711

Affected Products

Ibm Spectrum Protect Plus