CVE-2020-4213: IBM Spectrum Protect Plus username Command Injection Remote Code Execution Vulnerability
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024.
Other sources
IBM Spectrum Protect Plus could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4213?
CVE-2020-4213 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of IBM Spectrum Protect Plus.
How severe is CVE-2020-4213?
CVE-2020-4213 has a severity rating of 9.8 out of 10, which is classified as critical.
Which software is affected by CVE-2020-4213?
IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5 are affected by CVE-2020-4213.
How can CVE-2020-4213 be exploited?
CVE-2020-4213 can be exploited by remote attackers without authentication through the Administrative Console Framework service.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2020-4213?
The CWE ID associated with CVE-2020-4213 is CWE-78, which refers to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').