CVE-2020-4257: High severity ibm i2 analyst's notebook premium vulnerability
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175635.
Other sources
IBM i2 Intelligent Analyis Platform could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4257?
The severity of CVE-2020-4257 is high with a CVSS score of 7.8.
How does CVE-2020-4257 impact IBM i2 Intelligent Analyis Platform?
CVE-2020-4257 allows a local attacker to execute arbitrary code on the system by exploiting a memory corruption vulnerability in IBM i2 Intelligent Analyis Platform 9.2.1.
How can an attacker exploit CVE-2020-4257?
An attacker can exploit CVE-2020-4257 by persuading a victim to open a specially-crafted file, which triggers the vulnerability and allows the execution of arbitrary code on the system.
Is there a patch available for CVE-2020-4257?
Yes, a patch is available for CVE-2020-4257. You can download it from IBM's Fix Central website using the provided URL.
Where can I find more information about CVE-2020-4257?
You can find more information about CVE-2020-4257 on IBM's X-Force Exchange website and the IBM Support pages.