IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. IBM X-Force ID: 181725.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6221358 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/181725 | vdb entry vendor advisory |
https://www.tenable.com/security/research/tra-2020-37 | third party advisory |