CVE-2020-4433
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD
Description
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.
Affected (10)
Products: Ibm: Aspera Application Platform On Demand, Aspera Faspex On Demand, Aspera High Speed Transfer Endpoint, Aspera High Speed Transfer Server, Aspera High Speed Transfer Server For Cloud Pak For Integration, Aspera Proxy Server, Aspera Server On Demand, Aspera Shares On Demand, Aspera Streaming, Aspera Transfer Cluster Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.7.4 | |
| Up to 3.7.4 | |
| Up to 3.9.3 | |
| Up to 3.9.3 | |
| Up to 3.9.10 | |
| Up to 1.4.3 | |
| Up to 3.7.4 | |
| Up to 3.7.4 | |
| Up to 3.9.3 | |
| Up to 1.3.1 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (4)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.