CVE-2020-4434
7.5HIGH
Key Information:
- Vendor
- IBM
- Status
- Vendor
- CVE Published:
- 10 June 2020
Summary
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900.
Affected Version(s)
Aspera Application Platform On Demand 3.7.4
Aspera Faspex On Demand 3.7.4
Aspera High-Speed Transfer Endpoint 3.9.3
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved