CVE-2020-4242: OS Command Injection
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419.
Other sources
IBM Spectrum Scale and IBM Spectrum Protect Plus could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4242?
The severity of CVE-2020-4242 is rated as high due to its ability to allow remote command execution by authenticated attackers.
How do I fix CVE-2020-4242?
To fix CVE-2020-4242, you should upgrade IBM Spectrum Scale or IBM Spectrum Protect Plus to versions 10.1.6 or later.
Who is affected by CVE-2020-4242?
CVE-2020-4242 affects users of IBM Spectrum Scale and IBM Spectrum Protect Plus versions 10.1.0 to 10.1.5.
What types of systems are vulnerable to CVE-2020-4242?
Systems running IBM Spectrum Scale and IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5 are vulnerable to CVE-2020-4242.
Can CVE-2020-4242 be exploited remotely?
Yes, CVE-2020-4242 can be exploited remotely by authenticated attackers to execute arbitrary commands.