CVE-2020-4703
HIGHIBM Spectrum Protect Plus < 10.1.6 - Unrestricted File Upload
Title source: ruleDescription
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6328867
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/187188
Scores
CVSS v3
8.0
EPSS
0.0084
EPSS Percentile
74.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
ibm/spectrum_protect_plus
10.1.0 - 10.1.6
Published
Sep 15, 2020
Tracked Since
Feb 18, 2026