CVE-2020-4433
—CVSS 3.1
7.5 high
EPSS
5%p92
Published
()
Modified
Description
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.
- Vendors
- ibm
- Products
- aspera application platform on demand, aspera faspex on demand, aspera high-speed transfer endpoint, aspera high-speed transfer server, aspera high-speed transfer server for cloud pak for integration, aspera proxy server, aspera server on demand, aspera shares on demand, aspera streaming, aspera transfer cluster manager
- Weakness
- CWE-20, CWE-787
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.