PublicCVE

CVE-2020-4470

HIGH7.1JSON exportCreate alert

Description

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. IBM X-Force ID: 181725.

CVSS breakdown

CVSS 3.0
Availability
High
Integrity
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Privileges Required
Low
Attack Complexity
High
Attack Vector
Network
RL
O
E
Unchanged
RC
Changed

Affected products