CVE-2020-4470
CVE-2020-4470
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 1.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Jun 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. IBM X-Force ID: 181725.
CVSS:3.0/A:H/I:H/UI:R/S:U/C:H/PR:L/AC:H/AV:N/RL:O/E:U/RC:C
Affected products
IBM · Spectrum Protect PlusWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →