PT-2021-12252 · Ibm · Ibm Spectrum Protect Operations Center

Published

2021-02-15

·

Updated

2021-02-17

·

CVE-2020-4955

CVSS v3.1

8.0

High

VectorC:H/S:C/A:H/AC:H/PR:L/UI:N/AV:A/I:H
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Operations Center versions 7.1 through 8.1
Description The issue is caused by improper parameter validation, allowing a remote attacker to execute arbitrary code on the system. An attacker could exploit this by creating an unspecified servlet request with specially crafted input parameters to load a malicious .dll with elevated privileges.
Recommendations For versions 7.1 and 8.1, consider disabling the servlet request functionality until a patch is available to prevent exploitation. Restrict access to the system to minimize the risk of loading malicious .dll files with elevated privileges.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4955

Affected Products

Ibm Spectrum Protect Operations Center