CVE-2020-4469: OS Command Injection
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. This vulnerability is due to an incomplete fix for CVE-2020-4211. IBM X-Force ID: 181724.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4469?
CVE-2020-4469 is a vulnerability in IBM Spectrum Protect Plus 10.1.0 through 10.1.5 that could allow a remote attacker to execute arbitrary code on the system.
How does the vulnerability in IBM Spectrum Protect Plus 10.1.0 through 10.1.5 work?
The vulnerability allows a remote attacker to execute arbitrary commands on the system by using a specially crafted HTTP command.
What is the severity of CVE-2020-4469?
The severity of CVE-2020-4469 is critical with a CVSS score of 9.8.
How can an attacker exploit CVE-2020-4469?
An attacker can exploit CVE-2020-4469 by sending a specially crafted HTTP command to the vulnerable system.
Is there a fix available for CVE-2020-4469?
Yes, IBM has released fixes for this vulnerability. Please refer to the IBM advisory for more information on the available patches.