First published: Mon Jun 08 2020(Updated: )
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera High-Speed Transfer Server | <=3.9.3 and earlier | |
IBM Aspera High-Speed Transfer Endpoint | <=3.9.3 and earlier | |
IBM Aspera Proxy Server | <=1.4.3 and earlier | |
IBM Aspera Transfer Cluster Manager | <=1.3.1 with Aspera High-Speed Transfer Server 3.9.3 and earlier | |
IBM Aspera Application Platform On Demand | <=3.7.4 and earlier | |
IBM Aspera Faspex On Demand | <=3.7.4 and earlier | |
IBM Aspera Server On Demand | <=3.7.4 and earlier | |
IBM Aspera Shares On Demand | <=3.7.4 and earlier | |
IBM Aspera Streaming | <=3.9.3 and earlier | |
IBM Aspera High-Speed Transfer Server for Cloud Pak for Integration (CP4I) | <=3.9.10 and earlier | |
IBM Aspera Application Platform On Demand | <=3.7.4 | |
IBM Aspera Faspex On Demand | <=3.7.4 | |
IBM Aspera High-Speed Transfer Endpoint | <=3.9.3 | |
IBM Aspera High-Speed Transfer Server | <=3.9.3 | |
Ibm Aspera High-speed Transfer Server For Cloud Pak For Integration | <=3.9.10 | |
IBM Aspera Proxy Server | <=1.4.3 | |
IBM Aspera Server On Demand | <=3.7.4 | |
IBM Aspera Shares On Demand | <=3.7.4 | |
IBM Aspera Streaming | <=3.9.3 | |
IBM Aspera Transfer Cluster Manager | <=1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4432 is classified as a high severity vulnerability due to its potential for command injection after valid authentication.
To fix CVE-2020-4432, upgrade to the latest versions of the affected IBM Aspera applications that address this vulnerability.
CVE-2020-4432 affects IBM Aspera High-Speed Transfer Server, High-Speed Transfer Endpoint, Proxy Server, and several other Aspera applications up to specific versions.
Yes, CVE-2020-4432 can be exploited remotely by an attacker who has valid authentication to the system.
The potential impacts of CVE-2020-4432 include unauthorized command execution in systems running vulnerable IBM Aspera applications.