CVE-2020-4240: Path Traversal
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417.
Other sources
IBM Spectrum Protect Plus could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4240?
CVE-2020-4240 has been rated with a medium severity level due to its potential for unauthorized file manipulation.
How do I fix CVE-2020-4240?
To mitigate CVE-2020-4240, update IBM Spectrum Protect Plus to version 10.1.6 or later.
What does CVE-2020-4240 allow an attacker to do?
CVE-2020-4240 allows a remote attacker to traverse directories and potentially overwrite or create arbitrary files on the system.
What versions of IBM Spectrum Protect Plus are affected by CVE-2020-4240?
CVE-2020-4240 affects IBM Spectrum Protect Plus versions from 10.1.0 to 10.1.5.
Is CVE-2020-4240 an exploit that requires authentication?
CVE-2020-4240 can be exploited remotely and does not necessarily require authentication to perform the directory traversal attack.