CVE-2020-4206
published 2020-03-31CVE-2020-4206: IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused…
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.61%
90.6th percentile
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | spectrum_protect_plus | — | — |
| ibm | spectrum_protect_plus | — | — |
| ibm | spectrum_protect_plus | 10.1.0 – 10.1.5 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15961 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-09-22·CVSS 9.6
CVE-2020-15961 [CRITICAL] CVE-2020-15961 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-15961 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1114636
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1881603]
Affects: fedora-all [bug 1881602]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4206 https://access.redhat.com/errata/RHSA-2020:4206
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.re
Bugzilla
CVE-2020-15964 chromium-browser: Insufficient data validation in media
bugzilla·2020-09-22·CVSS 8.8
CVE-2020-15964 [HIGH] CVE-2020-15964 chromium-browser: Insufficient data validation in media
CVE-2020-15964 chromium-browser: Insufficient data validation in media
An insufficient data validation flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1121414
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1881603]
Affects: fedora-all [bug 1881602]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4206 https://access.redhat.com/errata/RHSA-2020:4206
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securit
Bugzilla
CVE-2020-15966 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-09-22·CVSS 4.3
CVE-2020-15966 [MEDIUM] CVE-2020-15966 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-15966 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1113565
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1881603]
Affects: fedora-all [bug 1881602]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4206 https://access.redhat.com/errata/RHSA-2020:4206
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.re
Bugzilla
CVE-2020-15965 chromium-browser: Out of bounds write in V8
bugzilla·2020-09-22·CVSS 8.8
CVE-2020-15965 [HIGH] CVE-2020-15965 chromium-browser: Out of bounds write in V8
CVE-2020-15965 chromium-browser: Out of bounds write in V8
An out of bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1126249
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1881603]
Affects: fedora-all [bug 1881602]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4206 https://access.redhat.com/errata/RHSA-2020:4206
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15965
Bugzilla
CVE-2020-15962 chromium-browser: Insufficient policy enforcement in serial
bugzilla·2020-09-22·CVSS 8.8
CVE-2020-15962 [HIGH] CVE-2020-15962 chromium-browser: Insufficient policy enforcement in serial
CVE-2020-15962 chromium-browser: Insufficient policy enforcement in serial
An insufficient policy enforcement flaw was found in the serial component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1121836
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1881603]
Affects: fedora-all [bug 1881602]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4206 https://access.redhat.com/errata/RHSA-2020:4206
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com
Bugzilla
CVE-2020-15963 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-09-22·CVSS 9.6
CVE-2020-15963 [CRITICAL] CVE-2020-15963 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-15963 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1113558
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1881603]
Affects: fedora-all [bug 1881602]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4206 https://access.redhat.com/errata/RHSA-2020:4206
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.re
Bugzilla
CVE-2020-15960 chromium-browser: Out of bounds read in storage
bugzilla·2020-09-22·CVSS 8.8
CVE-2020-15960 [HIGH] CVE-2020-15960 chromium-browser: Out of bounds read in storage
CVE-2020-15960 chromium-browser: Out of bounds read in storage
An out of bounds read flaw was found in the storage component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1100136
External References:
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1881603]
Affects: fedora-all [bug 1881602]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4206 https://access.redhat.com/errata/RHSA-2020:4206
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-1
2020-03-31
Published