#VU26557 Input validation error in IBM Spectrum Protect Plus - CVE-2020-4214
Published: April 3, 2020 / Updated: April 4, 2020
IBM Spectrum Protect Plus
IBM Corporation
Description
The vulnerability allows a remote attacker to delete arbitrary directories.
The vulnerability exists due to insufficient validation of user-supplied input via "cleanupUpdateImage" in the Administrative Console Framework service. A remote attacker can pass specially crafted input to the application and delete arbitrary directories on the target system.