There is a vulnerability in Apache Commons used by IBM Sterling Connect:Direct File Agent. IBM Sterling Connect:Direct File Agent has addressed the applicable CVE.
CVEID:CVE-2020-1953
**DESCRIPTION:**Apache Commons Configuration could allow a remote attacker to execute arbitrary code on the system, caused by an issue when allowing the instantiation of classes (including special statements) by default. By persuading a victim to load a specially-crafted YAML file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177759 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
Sterling Connect Direct File Agent | 1.4.0.0 - 1.4.0.2_iFix007 |
Affected Product(s) | Version(s) | APAR | Remediation / First Fix |
---|---|---|---|
Sterling Connect Direct File Agent | 1.4 | IT37680 | Apply 1.4.0.2_iFix008 or later, available on Fix Central |
For unsupported versions IBM recommends upgrading to a fixed, supported version of the product. |
None
CPE | Name | Operator | Version |
---|---|---|---|
sterling connect:direct file agent | eq | 1.4 |