CVE-2020-4703
CVE-2020-4703
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8EPSS 1.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Sep 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.
CVSS:3.0/PR:L/C:H/UI:R/I:H/AV:N/S:U/AC:L/A:H/RL:O/RC:C/E:U
Affected products
IBM · Spectrum Protect PlusWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →