CVE-2020-4955: Malicious File Upload
IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an unspecified servlet request with specially crafted input parameters, an attacker could exploit this vulnerability to load a malicious .dll with elevated privileges. IBM X-Force ID: 192155.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for IBM Spectrum Protect Operations Center?
The vulnerability ID for IBM Spectrum Protect Operations Center is CVE-2020-4955.
What is the severity of CVE-2020-4955?
The severity of CVE-2020-4955 is high.
Which versions of IBM Spectrum Protect Operations Center are affected by CVE-2020-4955?
IBM Spectrum Protect Operations Center versions 7.1.0.000 to 7.1.13.000 and versions 8.1.0.000 to 8.1.10.200 are affected by CVE-2020-4955.
How can a remote attacker exploit CVE-2020-4955?
A remote attacker can exploit CVE-2020-4955 by creating an unspecified servlet request with specially crafted input parameters.
Are there any references for CVE-2020-4955?
Yes, you can find references for CVE-2020-4955 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/192155) and [Reference 2](https://www.ibm.com/support/pages/node/6404966).