Improper access control in IBM Spectrum Virtualize - CVE-2020-4686
Published: August 17, 2020
Vulnerability identifier: #VU45746
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4686
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user authenticated via LDAP can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
IBM Spectrum Virtualize
SAN Volume Controller and Storwize Family
SAN Volume Controller and Storwize Family
How to mitigate CVE-2020-4686
Install updates from vendor's website.
SAN Volume Controller and Storwize Family - update to 8.3.1.2