CVE-2020-4206: Input Validation
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966.
Other sources
IBM Spectrum Protect Plus could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4206?
CVE-2020-4206 is considered critical due to the potential for remote command execution as a root user.
How do I fix CVE-2020-4206?
To fix CVE-2020-4206, upgrade IBM Spectrum Protect Plus to version 10.1.6 or later.
What systems are affected by CVE-2020-4206?
CVE-2020-4206 affects IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5.
What type of vulnerability is CVE-2020-4206?
CVE-2020-4206 is a remote command execution vulnerability caused by improper validation of user-supplied input.
Can CVE-2020-4206 be exploited remotely?
Yes, CVE-2020-4206 can be exploited remotely by an attacker to execute arbitrary commands.