CVE-2020-4436

HIGH

IBM Aspera Application Platform ON Demand < 3.7.4 - Buffer Overflow

Title source: rule
STIX 2.1

Description

Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6221324
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/180902

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (10)
ibm/aspera_application_platform_on_demand < 3.7.4
ibm/aspera_faspex_on_demand < 3.7.4
ibm/aspera_high-speed_transfer_endpoint < 3.9.3
ibm/aspera_high-speed_transfer_server < 3.9.3
ibm/aspera_high-speed_transfer_server_for_cloud_pak_for_integration < 3.9.10
ibm/aspera_proxy_server < 1.4.3
ibm/aspera_server_on_demand < 3.7.4
ibm/aspera_shares_on_demand < 3.7.4
ibm/aspera_streaming < 3.9.3
ibm/aspera_transfer_cluster_manager < 1.3.1
Published Jun 10, 2020
Tracked Since Feb 18, 2026