CVE-2021-39065: OS Command Injection
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote attacker could inject arbitrary shell commands which would be executed on the affected system. IBM X-Force ID: 214958.
Other sources
IBM Spectrum Copy Data Management could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote attacker could inject arbitrary shell commands which would be executed on the affected system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-39065.
What is the severity of CVE-2021-39065?
The severity of CVE-2021-39065 is critical with a score of 9.8.
Which software is affected by CVE-2021-39065?
IBM Spectrum Copy Data Management versions 2.2.13 and earlier are affected by this vulnerability.
How can a remote attacker exploit CVE-2021-39065?
A remote attacker can exploit CVE-2021-39065 by executing arbitrary commands on the system.
Are there any fixes or patches available for CVE-2021-39065?
Please refer to the IBM Support website for information on available fixes or patches for CVE-2021-39065.