4.8
CVSSv2

CVE-2020-4954

Published: 15/02/2021 Updated: 17/02/2021
CVSS v2 Base Score: 4.8 | Impact Score: 4.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 427
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote malicious user to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker controlled IBM Spectrum Protect server, an attacker could exploit this vulnerability to bypass authentication and gain access to a limited number of debug functions, such as logging levels. IBM X-Force ID: 192153.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm spectrum protect operations center