CVE-2020-4211: IBM Spectrum Protect Plus hostname Command Injection Remote Code Execution Vulnerability
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.
Other sources
IBM Spectrum Protect Plus could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4211.
What is the severity of CVE-2020-4211?
The severity of CVE-2020-4211 is critical with a CVSS score of 9.8.
What is the affected software?
The affected software is IBM Spectrum Protect Plus version 10.1.0 to 10.1.5.
Is authentication required to exploit CVE-2020-4211?
No, authentication is not required to exploit CVE-2020-4211.
How can I fix CVE-2020-4211?
To fix CVE-2020-4211, apply the necessary patches and updates provided by IBM.