CVE-2020-4263
published 2020-05-14CVE-2020-4263: IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.42%
33.9th percentile
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175646.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| ibm | i2_analysts_notebook | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_apache7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-864v-vr6f-7f4j: IBM i2 Intelligent Analyis Platform 9
ghsa_unreviewed·2022-05-24
CVE-2020-4263 [MEDIUM] CWE-119 GHSA-864v-vr6f-7f4j: IBM i2 Intelligent Analyis Platform 9
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175646.
Apache
Apache nifi: CVE-2020-9491
vendor_apache·CVSS 7.5
CVE-2020-9491 [HIGH] Apache nifi: CVE-2020-9491
Apache nifi: CVE-2020-9491
Title: Insecure TLS Protocol Versions for Cluster Communication Published: 2020-08-18 Severity: High Products: Apache NiFi Affected Versions: 1.2.0 to 1.11.4 Fixed Versions: 1.12.0 Reporter: Juan Carlos Sequeiros and Andy LoPresto References CVE Record: CVE-2020-9491 NVD Record: CVE-2020-9491 Apache Jira Issue: NIFI-7407 GitHub Pull Request: 4263 The NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP and HandleHttpRequest. However intra-cluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS 1.0 or 1.1. NiFI 1.12.0 refactored disparate internal SSL and TLS code, reducing exposure for extension and framework developers to
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-05-14
Published