CVE-2020-4435: High severity IBM Aspera High-Speed Transfer Server vulnerability
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4435?
CVE-2020-4435 is rated as a critical vulnerability due to its potential for arbitrary code execution and denial-of-service attacks.
How do I fix CVE-2020-4435?
To fix CVE-2020-4435, update the affected IBM Aspera applications to the latest versions as recommended by IBM.
What IBM products are affected by CVE-2020-4435?
CVE-2020-4435 affects multiple IBM Aspera products including Aspera High-Speed Transfer Server, Aspera Proxy Server, and others up to specified versions.
Can CVE-2020-4435 be exploited remotely?
Yes, CVE-2020-4435 can potentially be exploited remotely if an attacker has knowledge of the system configuration.
What types of attacks can be conducted using CVE-2020-4435?
CVE-2020-4435 can allow attackers to conduct arbitrary code execution or perform denial-of-service (DoS) attacks.