IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/187188 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/6328867 | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2020-09-14T00:00:00
Updated: 2020-09-15T13:50:25
Reserved: 2019-12-30T00:00:00
Link: CVE-2020-4703
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-09-15T14:15:14.690
Modified: 2020-09-16T00:46:19.853
Link: CVE-2020-4703
JSON object: View
Redhat Information
No data.
CWE