First published: Mon Mar 30 2020(Updated: )
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Storage Protect Plus | <=10.1.0-10.1.5 | |
IBM Storage Protect Plus | >=10.1.0<=10.1.5 | |
IBM Spectrum Scale | >=10.1.0<=10.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4242 is rated as high due to its ability to allow remote command execution by authenticated attackers.
To fix CVE-2020-4242, you should upgrade IBM Spectrum Scale or IBM Spectrum Protect Plus to versions 10.1.6 or later.
CVE-2020-4242 affects users of IBM Spectrum Scale and IBM Spectrum Protect Plus versions 10.1.0 to 10.1.5.
Systems running IBM Spectrum Scale and IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5 are vulnerable to CVE-2020-4242.
Yes, CVE-2020-4242 can be exploited remotely by authenticated attackers to execute arbitrary commands.