First published: Fri Nov 20 2020(Updated: )
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 190454.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | >=10.1.0<=10.1.6 | |
Linux Linux kernel | ||
<=10.1.0-10.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4854 is critical with a CVSS score of 9.8.
CVE-2020-4854 allows an attacker to gain unauthorized access, perform unauthorized actions, or decrypt internal data.
CVE-2020-4854 affects IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6 by containing hard-coded credentials.
Linux systems are not vulnerable to CVE-2020-4854.
To fix CVE-2020-4854, upgrade IBM Spectrum Protect Plus to a version beyond 10.1.6.