CVE-2020-4213 – IBM Spectrum Protect Plus username Command Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-4213
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024. IBM Spectrum Protect Plus versiones 10.1.0 y 10.1.5, podría permitir a un atacante remoto ejecutar código arbitrario sobre el sistema. Mediante el uso de un comando HTTP especialmente diseñado, un atacante podría explotar esta vulnerabilidad para ejecutar un comando arbitrario sobre el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/175024 https://www.ibm.com/support/pages/node/3178863 https://www.zerodayinitiative.com/advisories/ZDI-20-270 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2020-4212 – IBM Spectrum Protect Plus hfpackage Command Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-4212
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023. IBM Spectrum Protect Plus versiones 10.1.0 y 10.1.5, podría permitir a un atacante remoto ejecutar código arbitrario sobre el sistema. Mediante el uso de un comando HTTP especialmente diseñado, un atacante podría explotar esta vulnerabilidad para ejecutar un comando arbitrario sobre el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/175023 https://www.ibm.com/support/pages/node/3178863 https://www.zerodayinitiative.com/advisories/ZDI-20-272 • CWE-20: Improper Input Validation •
CVE-2020-4211 – IBM Spectrum Protect Plus hostname Command Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-4211
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022. IBM Spectrum Protect Plus versiones 10.1.0 y 10.1.5, podría permitir a un atacante remoto ejecutar código arbitrario sobre el sistema. Mediante el uso de un comando HTTP especialmente diseñado, un atacante podría explotar esta vulnerabilidad para ejecutar un comando arbitrario sobre el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/175022 https://www.ibm.com/support/pages/node/3178863 https://www.zerodayinitiative.com/advisories/ZDI-20-273 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2020-4210 – IBM Spectrum Protect Plus changeAdministratorPassword Command Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-4210
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175020. IBM Spectrum Protect Plus versiones 10.1.0 y 10.1.5, podría permitir a un atacante remoto ejecutar código arbitrario sobre el sistema. Mediante el uso de un comando HTTP especialmente diseñado, un atacante podría explotar esta vulnerabilidad para ejecutar un comando arbitrario sobre el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/175020 https://www.ibm.com/support/pages/node/3178863 https://www.zerodayinitiative.com/advisories/ZDI-20-274 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2019-4703
https://notcve.org/view.php?id=CVE-2019-4703
IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information. IBM Spectrum Protect Plus versiones 10.1.0 y 10.5.0, cuando protege a Microsoft SQL o Microsoft Exchange, podría permitir a un atacante con un conocimiento intimo del sistema obtener información altamente confidencial. • https://exchange.xforce.ibmcloud.com/vulnerabilities/172013 https://www.ibm.com/support/pages/node/3177915 •