CVE-2020-4285: Critical severity ibm i2 analyst's notebook premium vulnerability
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 176266
Other sources
IBM i2 Intelligent Analyis Platform could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4285?
CVE-2020-4285 is considered a critical vulnerability that allows remote code execution due to a memory corruption error.
How do I mitigate CVE-2020-4285?
To mitigate CVE-2020-4285, users should upgrade to a patched version of IBM i2 Analysts Notebook that addresses this vulnerability.
What versions of IBM i2 Analysts Notebook are affected by CVE-2020-4285?
CVE-2020-4285 affects IBM i2 Analysts Notebook versions up to and including 9.2.1.
Can CVE-2020-4285 be exploited remotely?
Yes, CVE-2020-4285 can be exploited remotely by persuading the victim to open a specially-crafted document.
What type of vulnerability is CVE-2020-4285?
CVE-2020-4285 is categorized as a remote code execution vulnerability.