CVE-2020-4981: Input Validation
Published Apr 23, 2021
·Updated
IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 192541.
Other sources
IBM Spectrum Scale could allow a local privileged user to overwrite files due to improper input validation.
— IBM
Affected Software
2 affected components
IBM Spectrum Scale>=5.0.4.1<=5.1.0.3
IBM Spectrum Scale<=5.0.4.1 - 5.1.0.3 (CSI V1.0.0 - V2.1.0)
Remediation
Patch Available
Event History
Apr 23, 2021
CVE Published
via IBM·12:00 AM
Apr 27, 2021
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4981.
2
What is the affected software?
The affected software is IBM Spectrum Scale versions 5.0.4.1 through 5.1.0.3.
3
How can a local privileged user exploit this vulnerability?
A local privileged user can exploit this vulnerability to overwrite files due to improper input validation.
4
What is the severity of CVE-2020-4981?
The severity of CVE-2020-4981 is medium (CVSS score: 6.0).
5
How can I fix this vulnerability?
To fix this vulnerability, update IBM Spectrum Scale to a version that is not affected (5.1.0.4 or later).