Lucene search

K
ibmIBM71ABDA700E34ED1E5E05E19B2B8B2EF465A79F052892B425E6581F859048037F
HistoryNov 20, 2020 - 8:13 p.m.

Security Bulletin: Vulnerability in Python affects IBM Spectrum Protect Plus Microsoft Windows File Systems agent (CVE-2020-15801)

2020-11-2020:13:28
www.ibm.com
14

0.003 Low

EPSS

Percentile

69.4%

Summary

There is a vulnerability in Python that could allow a local attacker to execute arbitrary code on the system. This vulnerability may affect the IBM Spectrum Protect Plus Microsoft® Windows File Systems agent.

Vulnerability Details

CVEID:CVE-2020-15801
**DESCRIPTION:**Python could allow a local attacker to execute arbitrary code on the system, caused by an issue with sys.path restrictions specified in a python38._pth file are ignored. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185561 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Plus 10.1.6

Remediation/Fixes

Spectrum Protect Plus Release First Fixing VRM Level Platform Link to Fix
10.1 10.1.7 Windows <https://www.ibm.com/support/pages/node/6330495&gt;

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm spectrum protect pluseq10.1.6

0.003 Low

EPSS

Percentile

69.4%

Related for 71ABDA700E34ED1E5E05E19B2B8B2EF465A79F052892B425E6581F859048037F