Remote Code Execution Vulnerability in IBM Spectrum Copy Data Management
CVE-2021-39065
8.1HIGH
Summary
IBM Spectrum Copy Data Management versions 2.2.13 and earlier are susceptible to a security flaw that enables remote attackers to execute arbitrary commands on affected systems. This vulnerability arises from inadequate validation of user-provided input within the Admin Console. By exploiting this weakness via the login and upload certificate functions, a malicious actor may inject shell commands that are executed by the system, compromising its integrity. Proper mitigation strategies should be employed to protect systems from potential exploitation.
Affected Version(s)
Spectrum Copy Data Management 2.2.13
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved