CVE-2020-4241: OS Command Injection
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418.
Other sources
IBM Spectrum Scale and IBM Spectrum Protect Plus could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4241?
The severity of CVE-2020-4241 is critical.
How can a remote authenticated attacker exploit CVE-2020-4241?
A remote authenticated attacker can exploit CVE-2020-4241 by sending a specially crafted request to execute arbitrary commands on the system.
Which versions of IBM Spectrum Protect Plus are affected by CVE-2020-4241?
IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5 are affected by CVE-2020-4241.
Which versions of IBM Spectrum Scale are affected by CVE-2020-4241?
IBM Spectrum Scale versions 10.1.0 through 10.1.5 are affected by CVE-2020-4241.
Are there any references for CVE-2020-4241?
Yes, you can find references for CVE-2020-4241 at the following links: [IBM X-Force](https://exchange.xforce.ibmcloud.com/vulnerabilities/175418), [IBM Support](https://www.ibm.com/support/pages/node/6114130).