CVE-2020-4956 is a denial-of-service vulnerability affecting IBM Spectrum Protect Operations Center versions 7.1 and 8.1. A remote attacker with low privileges can exploit a flaw in the RPC mechanism by repeatedly setting and dumping a large cache value, leading to the consumption of all memory resources. This vulnerability has a CVSS score of 4.8 (Medium) due to its network-adjacent attack vector and high impact on availability, though it requires high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.1.0.000, < 7.1.13.000CPE matchmatch criteria | cpe:2.3:a:ibm:spectrum_protect_operations_center:*:*:*:*:*:*:*:* | ||
>= 8.1.0.000, < 8.1.10.200CPE matchmatch criteria | cpe:2.3:a:ibm:spectrum_protect_operations_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021IBM Spectrum Protect Operations Center 8.1.10 Multiple Vulnerabilities
Feb 15, 2021