#VU26559 Command Injection in IBM Spectrum Protect Plus - CVE-2020-4206
Published: April 3, 2020
IBM Spectrum Protect Plus
IBM Corporation
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists within the Administrative Console Framework service due to the process does not properly validate a user-supplied string before using it to execute a system call when parsing the "timezone" parameter. A remote authenticated attacker can send a specially crafted request and execute arbitrary commands on the system in the context of root.