PT-2021-12252 · Ibm · Ibm Spectrum Protect Operations Center
Published
2021-02-15
·
Updated
2021-02-17
·
CVE-2020-4955
CVSS v3.1
8.0
High
| Vector | C:H/S:C/A:H/AC:H/PR:L/UI:N/AV:A/I:H |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Operations Center versions 7.1 through 8.1
Description
The issue is caused by improper parameter validation, allowing a remote attacker to execute arbitrary code on the system. An attacker could exploit this by creating an unspecified servlet request with specially crafted input parameters to load a malicious .dll with elevated privileges.
Recommendations
For versions 7.1 and 8.1, consider disabling the servlet request functionality until a patch is available to prevent exploitation. Restrict access to the system to minimize the risk of loading malicious .dll files with elevated privileges.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect Operations Center