CVE-2020-4406: Medium severity IBM Spectrum Protect Client vulnerability
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.
Other sources
The IBM Spectrum Protect Backup-Archive Client web user interface and IBM Spectrum Protect for Space Management web user interface could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4406.
What is the severity of CVE-2020-4406?
The severity of CVE-2020-4406 is medium with a severity value of 5.4.
Which software products are affected by CVE-2020-4406?
IBM Spectrum Protect Client (version 8.1.7.0 through 8.1.9.1 on Linux and Windows, 8.1.9.0 through 8.1.9.1 on AIX), and IBM Spectrum Protect for Space Management (version 8.1.7.0 through 8.1.9.1 on Linux, 8.1.9.0 through 8.1.9.1 on AIX) are affected by CVE-2020-4406.
What is the description of CVE-2020-4406?
CVE-2020-4406 refers to a vulnerability in the web user interfaces of IBM Spectrum Protect Client and IBM Spectrum Protect for Space Management that could allow a remote attacker to hijack the clicking action of the victim.
Where can I find more information about CVE-2020-4406?
You can find more information about CVE-2020-4406 on the IBM X-Force Exchange website and the IBM Support Pages.