CVE-2020-4494
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow an attacker to bypass authentication due to improper session validation which can result in access to unauthorized resources. IBM X-Force ID: 182019.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.7.0 to 8.1.9.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.9.0 to 8.1.9.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.7.0 to 8.1.9.1 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.9.0 to 8.1.9.1 |
| Running on/with | Platform Versions |
|---|---|
Ibm Aix | All versions |
References (4)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.