CVE-2020-4432: Command Injection
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4432?
CVE-2020-4432 is classified as a high severity vulnerability due to its potential for command injection after valid authentication.
How do I fix CVE-2020-4432?
To fix CVE-2020-4432, upgrade to the latest versions of the affected IBM Aspera applications that address this vulnerability.
What applications are affected by CVE-2020-4432?
CVE-2020-4432 affects IBM Aspera High-Speed Transfer Server, High-Speed Transfer Endpoint, Proxy Server, and several other Aspera applications up to specific versions.
Can CVE-2020-4432 be exploited remotely?
Yes, CVE-2020-4432 can be exploited remotely by an attacker who has valid authentication to the system.
What are the potential impacts of CVE-2020-4432?
The potential impacts of CVE-2020-4432 include unauthorized command execution in systems running vulnerable IBM Aspera applications.