CVE-2020-4241OS Command Injection in IBM Spectrum Protect Plus

Severity
8.8HIGHNVD
EPSS
17.1%
top 4.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 24

Description

IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDibm/spectrum_protect_plus10.1.010.1.5
CVEListV5ibm/spectrum_protect_plus10.1.0, 10.1.5+1
NVDibm/spectrum_scale10.1.010.1.5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qj6m-554w-cmhg: IBM Spectrum Scale and IBM Spectrum Protect Plus 102022-05-24
CVEList
CVE-2020-4241: IBM Spectrum Scale and IBM Spectrum Protect Plus 102020-03-31