CVE-2020-4436
published 2020-06-10CVE-2020-4436: Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the…
PriorityP348high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
3.09%
86.2th percentile
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| ibm | aspera_application_platform_on_demand | <= 3.7.4 | — |
| ibm | aspera_application_platform_on_demand | — | — |
| ibm | aspera_faspex_on_demand | <= 3.7.4 | — |
| ibm | aspera_faspex_on_demand | — | — |
| ibm | aspera_high-speed_transfer_endpoint | <= 3.9.3 | — |
| ibm | aspera_high-speed_transfer_endpoint | — | — |
| ibm | aspera_high-speed_transfer_server | <= 3.9.3 | — |
| ibm | aspera_high-speed_transfer_server | — | — |
| ibm | aspera_high-speed_transfer_server_for_cloud_pak_for_integration | <= 3.9.10 | — |
| ibm | aspera_high-speed_transfer_server_for_cloud_pak_for_integration | — | — |
| ibm | aspera_proxy_server | <= 1.4.3 | — |
| ibm | aspera_proxy_server | — | — |
| ibm | aspera_server_on_demand | <= 3.7.4 | — |
| ibm | aspera_server_on_demand | — | — |
| ibm | aspera_shares_on_demand | <= 3.7.4 | — |
| ibm | aspera_shares_on_demand | — | — |
| ibm | aspera_streaming | <= 3.9.3 | — |
| ibm | aspera_streaming | — | — |
| ibm | aspera_transfer_cluster_manager | <= 1.3.1 | — |
| ibm | aspera_transfer_cluster_manager | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_apache5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9vrg-pr26-w94g: Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of
ghsa_unreviewed·2022-05-24
CVE-2020-4436 [MEDIUM] GHSA-9vrg-pr26-w94g: Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.
Apache
Apache nifi: CVE-2020-13940
vendor_apache·CVSS 5.5
CVE-2020-13940 [LOW] Apache nifi: CVE-2020-13940
Apache nifi: CVE-2020-13940
Title: Potential Information Disclosure through XML External Entity Resolution in Notification Service Published: 2020-08-18 Severity: Low Products: Apache NiFi Affected Versions: 1.0.0 to 1.11.4 Fixed Versions: 1.12.0 Reporter: Matt Burgess and Andy LoPresto References CVE Record: CVE-2020-13940 NVD Record: CVE-2020-13940 Apache Jira Issue: NIFI-7680 GitHub Pull Request: 4436 The notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services through XML External Entity resolution. NiFi 1.12.0 introduced an XML validator to prevent malicious code from being parsed and executed. Use
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-10
Published