7.5
CVE-2020-4435
- EPSS 0.95%
- Veröffentlicht 10.06.2020 13:15:17
- Zuletzt bearbeitet 21.11.2024 05:32:44
- Quelle psirt@us.ibm.com
- Teams Watchlist Login
- Unerledigt Login
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Aspera Application Platform On Demand Version <= 3.7.4
Ibm ≫ Aspera Faspex On Demand Version <= 3.7.4
Ibm ≫ Aspera High-speed Transfer Endpoint Version <= 3.9.3
Ibm ≫ Aspera High-speed Transfer Server Version <= 3.9.3
Ibm ≫ Aspera High-speed Transfer Server For Cloud Pak For Integration Version <= 3.9.10
Ibm ≫ Aspera Proxy Server Version <= 1.4.3
Ibm ≫ Aspera Server On Demand Version <= 3.7.4
Ibm ≫ Aspera Shares On Demand Version <= 3.7.4
Ibm ≫ Aspera Streaming Version <= 3.9.3
Ibm ≫ Aspera Transfer Cluster Manager Version <= 1.3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.95% | 0.754 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
psirt@us.ibm.com | 7.5 | 1.6 | 5.9 |
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.