CVE-2020-4686: High severity IBM Spectrum Virtualize vulnerability
Published Aug 17, 2020
·Updated
IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678.
Affected Software
22 affected components
IBM Spectrum Virtualize=8.3.1
IBM Spectrum Virtualize=8.3.1
IBM Flashsystem V5000 Firmware=8.3.1
IBM Flashsystem V5000
IBM Flashsystem V7200 Firmware=8.3.1
IBM Flashsystem V7200
IBM Flashsystem V9000 Firmware=8.3.1
IBM Flashsystem V9000
IBM Flashsystem V9100 Firmware=8.3.1
IBM Flashsystem V9100
IBM Flashsystem V9200 Firmware=8.3.1
IBM Flashsystem V9200
IBM San Volume Controller Firmware=8.3.1
IBM SAN Volume Controller
IBM Storwize V5000 Firmware=8.3.1
IBM Storwize V5000
IBM Storwize V5000e Firmware=8.3.1
IBM Storwize V5000e
IBM Storwize V5100 Firmware=8.3.1
IBM Storwize V5100
IBM Storwize V7000 Firmware=8.3.1
IBM Storwize V7000
Remediation
Patch Available
Event History
Aug 17, 2020
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-4686?
CVE-2020-4686 is a vulnerability in IBM Spectrum Virtualize 8.3.1 that allows a remote user authenticated via LDAP to escalate their privileges and perform unauthorized actions.
2
Which software versions are affected by CVE-2020-4686?
IBM Spectrum Virtualize 8.3.1 and its public cloud version are affected by CVE-2020-4686.
3
What is the severity rating of CVE-2020-4686?
CVE-2020-4686 has a severity rating of 8.1 (high).
4
How can a remote user exploit CVE-2020-4686?
A remote user authenticated via LDAP can exploit CVE-2020-4686 to escalate their privileges and perform unauthorized actions.
5
Where can I find more information about CVE-2020-4686?
You can find more information about CVE-2020-4686 on the IBM X-Force ID: 186678 and the IBM Support website.