CVE-2020-4212: IBM Spectrum Protect Plus hfpackage Command Injection Remote Code Execution Vulnerability
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023.
Other sources
IBM Spectrum Protect Plus could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4212?
CVE-2020-4212 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of IBM Spectrum Protect Plus.
How severe is CVE-2020-4212?
CVE-2020-4212 has a severity rating of 9.8 out of 10, which is considered critical.
Which software versions are affected by CVE-2020-4212?
Versions 10.1.0 through 10.1.5 of IBM Spectrum Protect Plus are affected by CVE-2020-4212.
Is authentication required to exploit CVE-2020-4212?
No, authentication is not required to exploit CVE-2020-4212.
How can I fix CVE-2020-4212?
To fix CVE-2020-4212, you should upgrade to a version of IBM Spectrum Protect Plus that is not affected by the vulnerability.