CVE-2021-39065
CVE-2021-39065
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 2.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 Dec 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote attacker could inject arbitrary shell commands which would be executed on the affected system. IBM X-Force ID: 214958.
CVSS:3.0/C:H/AV:N/I:H/UI:N/S:U/PR:N/A:H/AC:H/RL:O/RC:C/E:U
Affected products
IBM · Spectrum Copy Data ManagementWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →