First published: Wed Jan 20 2021(Updated: )
IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands. IBM X-Force ID: 192586.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum LSF Suite | =10.1 | |
IBM Spectrum LSF Suite Community Edition | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4983 is considered a high severity vulnerability due to its potential for unauthorized execution of arbitrary commands in IBM Spectrum LSF and IBM Spectrum LSF Suite.
To mitigate CVE-2020-4983, users should update their IBM Spectrum LSF to version 10.2 or apply any relevant security patches provided by IBM.
CVE-2020-4983 affects IBM Spectrum LSF version 10.1 and IBM Spectrum LSF Suite version 10.2.
No, CVE-2020-4983 requires a local user who has privileges to submit LSF jobs to exploit the vulnerability.
CVE-2020-4983 is a command injection vulnerability that allows users to execute arbitrary commands.