Ibm Aspera Application Platform On Demand vulnerabilities
5 known vulnerabilities affecting ibm/aspera_application_platform_on_demand.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5
Vulnerabilities
Page 1 of 1
CVE-2020-4433P3HIGHCVSS 7.5≤ 3.7.4v3.7.42020-06-10
CVE-2020-4433 [HIGH] CWE-20 CVE-2020-4433: Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.
nvd
CVE-2020-4432P3HIGHCVSS 7.5≤ 3.7.4v3.7.42020-06-10
CVE-2020-4432 [HIGH] CWE-77 CVE-2020-4432: Certain IBM Aspera applications are vulnerable to command injection after valid authentication, whic
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. IBM X-Force ID: 180810.
nvd
CVE-2020-4436P3HIGHCVSS 7.5≤ 3.7.4v3.7.42020-06-10
CVE-2020-4436 [HIGH] CWE-120 CVE-2020-4436: Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.
nvd
CVE-2020-4434P3HIGHCVSS 7.5≤ 3.7.4v3.7.42020-06-10
CVE-2020-4434 [HIGH] CWE-120 CVE-2020-4434: Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900.
nvd
CVE-2020-4435P3HIGHCVSS 7.5≤ 3.7.4v3.7.42020-06-10
CVE-2020-4435 [HIGH] CWE-787 CVE-2020-4435: Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product c
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901.
nvd