CVE-2020-4633: Input Validation
Published Nov 23, 2020
·Updated
IBM Resilient could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
Other sources
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
Affected Software
2 affected components
IBM Resilient Security Orchestration Automation And Response=38.0
IBM Resilient OnPrem<=IBM Security SOAR
Event History
Nov 23, 2020
CVE Published
via IBM·12:00 AM
Dec 11, 2020
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-4633?
The severity of CVE-2020-4633 is critical.
2
What software is affected by CVE-2020-4633?
IBM Resilient SOAR V38.0 and IBM Resilient OnPrem are affected by CVE-2020-4633.
3
How can a remote attacker exploit CVE-2020-4633?
CVE-2020-4633 can be exploited by a remote attacker to execute arbitrary code on the system.
4
What is the CWE ID for CVE-2020-4633?
The CWE ID for CVE-2020-4633 is 20 and 1236.
5
Where can I find more information about CVE-2020-4633?
You can find more information about CVE-2020-4633 in the IBM X-Force Exchange and IBM support pages.