CVE-2020-4494: High severity ibm storage protect backup-archive client vulnerability
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow an attacker to bypass authentication due to improper session validation which can result in access to unauthorized resources. IBM X-Force ID: 182019.
Other sources
The IBM Spectrum Protect Backup-Archive Client web user interface and IBM Spectrum Protect for Space Management web user interface could allow an attacker to bypass authentication due to improper session validation which can result in access to unauthorized resources.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4494?
CVE-2020-4494 is a vulnerability in the IBM Spectrum Protect Backup-Archive Client web user interface and IBM Spectrum Protect for Space Management web user interfaces that could allow an attacker to bypass authentication.
Which software versions are affected by CVE-2020-4494?
IBM Spectrum Protect Client versions 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 through 8.1.9.1 (AIX), and IBM Spectrum Protect for Space Management versions 8.1.7.0 through 8.1.9.1 (Linux), and 8.1.9.0 through 8.1.9.1 (AIX) are affected by CVE-2020-4494.
How severe is CVE-2020-4494?
CVE-2020-4494 has a severity rating of 7.5 (high).
How can I fix CVE-2020-4494?
Upgrade to a fixed version of IBM Spectrum Protect Client or IBM Spectrum Protect for Space Management that is not vulnerable to CVE-2020-4494.
Where can I find more information about CVE-2020-4494?
You can find more information about CVE-2020-4494 on the IBM X-Force Exchange website and the IBM support pages.