Show filters
45 Total Results
Displaying 31-40 of 45
Sort by:
Attacker Value
Unknown

CVE-2020-4469

Disclosure Date: June 12, 2020 (last updated February 21, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. This vulnerability is due to an incomplete fix for CVE-2020-4211. IBM X-Force ID: 181724.
Attacker Value
Unknown

CVE-2020-4471

Disclosure Date: June 12, 2020 (last updated February 21, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially crafted HTTP command to the remote server. IBM X-Force ID: 181726.
Attacker Value
Unknown

CVE-2020-4242

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419.
Attacker Value
Unknown

CVE-2020-4209

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to create arbitrary files on the system. IBM X-Force ID: 175019.
Attacker Value
Unknown

CVE-2020-4241

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418.
Attacker Value
Unknown

CVE-2020-4206

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966.
Attacker Value
Unknown

CVE-2020-4240

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417.
Attacker Value
Unknown

CVE-2020-4214

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026.
Attacker Value
Unknown

CVE-2020-4208

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.
Attacker Value
Unknown

CVE-2019-4703

Disclosure Date: February 21, 2020 (last updated November 27, 2024)
IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information.