ibm-spectrum-cve20204854-info-disc (190454)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/190454 CVE-2020-4854
CRITICAL
Record summary
CVE-2020-4854 has a selected CVSS score of 9.8 (critical).
Description
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 190454.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Spectrum Protect PlusBrowse IBM / Spectrum Protect Plus | CVE List | 10.1.0 | affected |
| 10.1.6 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-4854 ibm.comConfirmation
https://www.ibm.com/support/pages/node/6367823 tenable.com
https://www.tenable.com/security/research/tra-2020-66