CVE-2020-4470: Malicious File Upload
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. IBM X-Force ID: 181725.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4470?
CVE-2020-4470 is a vulnerability in IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console that could allow an authenticated attacker to upload arbitrary files and execute arbitrary code on the vulnerable server.
How severe is CVE-2020-4470?
CVE-2020-4470 has a severity score of 8, which is considered high.
How can an attacker exploit CVE-2020-4470?
An attacker with authentication can exploit CVE-2020-4470 by uploading arbitrary files and executing arbitrary code on the vulnerable server through the Administrative Console.
What versions of IBM Spectrum Protect Plus are affected by CVE-2020-4470?
IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5 are affected by CVE-2020-4470.
Are there any references for CVE-2020-4470?
Yes, you can find more information about CVE-2020-4470 at the following references: [IBM X-Force ID: 181725](https://exchange.xforce.ibmcloud.com/vulnerabilities/181725), [IBM Support Page](https://www.ibm.com/support/pages/node/6221358), and [Tenable Research Advisory](https://www.tenable.com/security/research/tra-2020-37).