First published: Mon Feb 15 2021(Updated: )
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker controlled IBM Spectrum Protect server, an attacker could exploit this vulnerability to bypass authentication and gain access to a limited number of debug functions, such as logging levels. IBM X-Force ID: 192153.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Operations Center | >=7.1.0.000<7.1.13.000 | |
IBM Spectrum Protect Operations Center | >=8.1.0.000<8.1.10.200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2020-4954.
The severity level of CVE-2020-4954 is medium (5.4).
IBM Spectrum Protect Operations Center versions 7.1 and 8.1 are affected by this vulnerability.
A remote attacker can exploit this vulnerability by bypassing authentication restrictions through improper session validation.
Yes, you can find more information about CVE-2020-4954 in the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/192153) and [Reference 2](https://www.ibm.com/support/pages/node/6404966).