First published: Mon Nov 23 2020(Updated: )
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 188993.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Operations Center | >=7.1.0.000<=7.1.11 | |
IBM Spectrum Protect Operations Center | >=8.1.0.000<=8.1.10 | |
IBM AIX | ||
Linux Kernel | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4771 is classified as a moderate severity vulnerability.
To fix CVE-2020-4771, upgrade IBM Spectrum Protect Operations Center to version 8.1.11 or later, or version 7.1.12 or later.
CVE-2020-4771 could allow a remote attacker to obtain sensitive information by exploiting improper authentication of a websocket endpoint.
CVE-2020-4771 affects IBM Spectrum Protect Operations Center versions 8.1.0.000 to 8.1.10 and 7.1.0.000 to 7.1.11.
An attacker can exploit CVE-2020-4771 by using known tools to subscribe to the websocket event stream.