PT-2020-5174 · Ibm · Ibm Spectrum Protect Plus

Published

2020-03-31

·

Updated

2021-07-21

·

CVE-2020-4206

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5
Description The issue is caused by improper validation of user-supplied input, allowing a remote attacker to execute arbitrary commands on the system in the context of the root user. This could potentially lead to privilege escalation and remote code execution.
Recommendations For IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5, update to a version outside of this range to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05787
CVE-2020-4206
ZDI-20-342

Affected Products

Ibm Spectrum Protect Plus