#VU26555 Command Injection in IBM Spectrum Scale and IBM Spectrum Protect Plus - CVE-2020-4241
Published: April 3, 2020
IBM Spectrum Scale
IBM Spectrum Protect Plus
IBM Corporation
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists within the Administrative Console Framework service due to the "uploadHttpsCertificate" method does not properly validate a user-supplied string before using it to execute a system call when parsing the "filename" parameter. A remote authenticated attacker can send a specially crafted request and execute arbitrary commands on the system.