First published: Tue Sep 15 2020(Updated: )
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | >=10.1.0<=10.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security vulnerability is CVE-2020-4703.
The severity of CVE-2020-4703 is high, with a severity value of 8.
The affected software for CVE-2020-4703 is IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6.
CVE-2020-4703 allows an authenticated attacker to upload arbitrary files and execute arbitrary code on the vulnerable server.
Yes, a fix for CVE-2020-4703 is available. Please refer to the IBM support page for more information.