IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6328867 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/187188 | vdb entry vendor advisory |