Remote Code Execution Vulnerability in IBM Spectrum Copy Data Management
CVE-2021-39065

8.1HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
13 December 2021

Summary

IBM Spectrum Copy Data Management versions 2.2.13 and earlier are susceptible to a security flaw that enables remote attackers to execute arbitrary commands on affected systems. This vulnerability arises from inadequate validation of user-provided input within the Admin Console. By exploiting this weakness via the login and upload certificate functions, a malicious actor may inject shell commands that are executed by the system, compromising its integrity. Proper mitigation strategies should be employed to protect systems from potential exploitation.

Affected Version(s)

Spectrum Copy Data Management 2.2.13

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.