7.5
CVSSv3

CVE-2020-4432

Published: 10/06/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. IBM X-Force ID: 180810.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm aspera high-speed transfer server for cloud pak for integration

ibm aspera shares on demand

ibm aspera server on demand

ibm aspera faspex on demand

ibm aspera application platform on demand

ibm aspera transfer cluster manager

ibm aspera proxy server

ibm aspera high-speed transfer server

ibm aspera streaming

ibm aspera high-speed transfer endpoint