CVE-2020-4214: Input Validation
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026.
Other sources
IBM Spectrum Protect Plus could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4214?
CVE-2020-4214 is considered a high severity vulnerability due to its potential to allow arbitrary directory deletion by remote attackers.
How do I fix CVE-2020-4214?
To fix CVE-2020-4214, upgrade IBM Spectrum Protect Plus to version 10.1.6 or later.
What versions of IBM Spectrum Protect Plus are affected by CVE-2020-4214?
CVE-2020-4214 affects IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5.
Can CVE-2020-4214 be exploited remotely?
Yes, CVE-2020-4214 can be exploited remotely by attackers due to improper validation of user-supplied input.
What type of attack is associated with CVE-2020-4214?
CVE-2020-4214 is associated with directory traversal attacks that can lead to arbitrary deletion of directories.