cbcvebase.
CVE-2020-4285
published 2020-05-14

CVE-2020-4285: IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error. By…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 176266

Affected

10 ranges
VendorProductVersion rangeFixed in
gnubinutils>= 0 < 2.34-6ubuntu1.72.34-6ubuntu1.7
gnubinutils>= 0 < 2.38-4ubuntu2.42.38-4ubuntu2.4
gnubinutils>= 0 < 2.24-5ubuntu14.2+esm62.24-5ubuntu14.2+esm6
gnugdb>= 0 < 9.2-0ubuntu1~20.04.29.2-0ubuntu1~20.04.2
gnugdb>= 0 < 12.1-0ubuntu1~22.04.212.1-0ubuntu1~22.04.2
gnugdb>= 0 < 7.11.1-0ubuntu1~16.5+esm17.11.1-0ubuntu1~16.5+esm1
gnugdb>= 0 < 8.1.1-0ubuntu1+esm18.1.1-0ubuntu1+esm1
ibmi2_analysts_notebook
msrccbl2_binutils_2.37-5_on_cbl_mariner_2.0
msrccm1_binutils_2.36.1-3_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH