CVE-2020-4955 is a high-severity vulnerability affecting IBM Spectrum Protect Operations Center versions 7.1 and 8.1, stemming from improper parameter validation. A remote attacker on the same network segment, with low privileges, can exploit this flaw by crafting a specific servlet request to load a malicious DLL, leading to arbitrary code execution with elevated privileges. This vulnerability carries a CVSS score of 8.0 (High), indicating significant potential for compromise (Confidentiality, Integrity, Availability). Despite its severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.1.0.000, < 7.1.13.000CPE matchmatch criteria | cpe:2.3:a:ibm:spectrum_protect_operations_center:*:*:*:*:*:*:*:* | ||
>= 8.1.0.000, < 8.1.10.200CPE matchmatch criteria | cpe:2.3:a:ibm:spectrum_protect_operations_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021