CVE-2020-4435
10.06.2020, 13:15
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | aspera_application_platform_on_demand | 𝑥 ≤ 3.7.4 |
ibm | aspera_faspex_on_demand | 𝑥 ≤ 3.7.4 |
ibm | aspera_high-speed_transfer_endpoint | 𝑥 ≤ 3.9.3 |
ibm | aspera_high-speed_transfer_server | 𝑥 ≤ 3.9.3 |
ibm | aspera_high-speed_transfer_server_for_cloud_pak_for_integration | 𝑥 ≤ 3.9.10 |
ibm | aspera_proxy_server | 𝑥 ≤ 1.4.3 |
ibm | aspera_server_on_demand | 𝑥 ≤ 3.7.4 |
ibm | aspera_shares_on_demand | 𝑥 ≤ 3.7.4 |
ibm | aspera_streaming | 𝑥 ≤ 3.9.3 |
ibm | aspera_transfer_cluster_manager | 𝑥 ≤ 1.3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration