Arbitrary File Upload Vulnerability in IBM Spectrum Protect Plus Administrative Console
CVE-2020-4703
8HIGH
What is CVE-2020-4703?
An authenticated attacker could exploit a flaw in the IBM Spectrum Protect Plus Administrative Console, versions 10.1.0 through 10.1.6, allowing them to upload arbitrary files. This could lead to the execution of arbitrary code on the vulnerable server, potentially compromising the integrity and availability of the system. This vulnerability stems from an incomplete fix for a previous issue (CVE-2020-4470) and highlights the importance of robust security measures.
Affected Version(s)
Spectrum Protect Plus 10.1.0
Spectrum Protect Plus 10.1.6