6 results (0.010 seconds)

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IBM X-Force ID: 193653. IBM Spectrum Protect Plus versiones 10.1.0 hasta 10.1.6, puede permitir a un usuario local conseguir acceso a información más allá de su rol y permisos previstos. IBM X-Force ID: 193653 • https://exchange.xforce.ibmcloud.com/vulnerabilities/193653 https://www.ibm.com/support/pages/node/6398754 •

CVSS: 10.0EPSS: 39%CPEs: 2EXPL: 0

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091. IBM Spectrum Protect Plus versiones 10.1.0 y 10.1.5, podría permitir a un atacante remoto ejecutar código arbitrario sobre el sistema. Mediante el uso de un comando HTTP especialmente diseñado, un atacante podría explotar esta vulnerabilidad para ejecutar un comando arbitrario sobre el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/175091 https://www.ibm.com/support/pages/node/3178863 https://www.zerodayinitiative.com/advisories/ZDI-20-271 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 10.0EPSS: 39%CPEs: 2EXPL: 0

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024. IBM Spectrum Protect Plus versiones 10.1.0 y 10.1.5, podría permitir a un atacante remoto ejecutar código arbitrario sobre el sistema. Mediante el uso de un comando HTTP especialmente diseñado, un atacante podría explotar esta vulnerabilidad para ejecutar un comando arbitrario sobre el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/175024 https://www.ibm.com/support/pages/node/3178863 https://www.zerodayinitiative.com/advisories/ZDI-20-270 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 10.0EPSS: 3%CPEs: 3EXPL: 0

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023. IBM Spectrum Protect Plus versiones 10.1.0 y 10.1.5, podría permitir a un atacante remoto ejecutar código arbitrario sobre el sistema. Mediante el uso de un comando HTTP especialmente diseñado, un atacante podría explotar esta vulnerabilidad para ejecutar un comando arbitrario sobre el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/175023 https://www.ibm.com/support/pages/node/3178863 https://www.zerodayinitiative.com/advisories/ZDI-20-272 • CWE-20: Improper Input Validation •

CVSS: 10.0EPSS: 39%CPEs: 3EXPL: 0

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022. IBM Spectrum Protect Plus versiones 10.1.0 y 10.1.5, podría permitir a un atacante remoto ejecutar código arbitrario sobre el sistema. Mediante el uso de un comando HTTP especialmente diseñado, un atacante podría explotar esta vulnerabilidad para ejecutar un comando arbitrario sobre el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/175022 https://www.ibm.com/support/pages/node/3178863 https://www.zerodayinitiative.com/advisories/ZDI-20-273 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •