Lucene search

K
ibmIBM31865EF723293A2349371BF2714FD31331970FD8BC69530649D080DD8C97A3D0
HistoryAug 03, 2020 - 10:40 p.m.

Security Bulletin: OpenSSH vulnerability affects IBM Spectrum Protect Plus (CVE-2020-15778)

2020-08-0322:40:43
www.ibm.com
233
openssh
ibm spectrum protect plus
cve-2020-15778
remote attacker
improper input validation
arbitrary commands
cvss 9.8
linux

EPSS

0.006

Percentile

78.5%

Summary

A vulnerability in OpenSSH may affect IBM Spectrum Protect Plus.

Vulnerability Details

CVEID:CVE-2020-15778
**DESCRIPTION:**OpenSSH could allow a remote attacker to execute arbitrary commands on the system, caused by improper input validation in the remote function in scp.c. By using backtick characters in the destination argument, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185805 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Plus 10.1.0-10.1.5

Remediation/Fixes

Spectrum Protect Plus Release First Fixing VRM Level Platform Link to Fix
10.1 10.1.6 Linux <https://www.ibm.com/support/pages/node/5693313&gt;

Workarounds and Mitigations

None