CVE-2020-4767: High severity ibm sterling connect:direct vulnerability
IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted request, the attacker could cause the application to crash. IBM X-Force ID: 188906.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4767?
CVE-2020-4767 is rated as a moderate severity vulnerability that can lead to a denial of service.
How do I fix CVE-2020-4767?
To mitigate CVE-2020-4767, it is recommended to upgrade to the latest version of IBM Sterling Connect:Direct.
What versions of IBM Sterling Connect:Direct are affected by CVE-2020-4767?
CVE-2020-4767 affects IBM Sterling Connect:Direct versions 4.7, 4.8, 6.0, and 6.1.
What type of attack does CVE-2020-4767 involve?
CVE-2020-4767 involves a buffer over-read that can be exploited to cause an application crash.
Can CVE-2020-4767 be exploited remotely?
Yes, CVE-2020-4767 allows a remote attacker to exploit the vulnerability through a specially crafted request.