Apache Commons Configuration is vulnerable to remote attack.
CVEID:CVE-2020-1953
**DESCRIPTION:**Apache Commons Configuration could allow a remote attacker to execute arbitrary code on the system, caused by an issue when allowing the instantiation of classes (including special statements) by default. By persuading a victim to load a specially-crafted YAML file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177759 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM Control Center | 6.2.0.0 |
Product|
VRMF
|
iFix
|
Remediation
—|—|—|—
IBM Control Center
|
6.2.0.0
|
iFix05
|
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm control center | eq | 6.2.0.0 |