CVE-2020-4494

EUVD-2020-25741
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow an attacker to bypass authentication due to improper session validation which can result in access to unauthorized resources. IBM X-Force ID: 182019.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ibmCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/I:N/A:N/S:U/UI:N/C:H/AC:L/PR:N/AV:N/RL:O/RC:C/E:U
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
ibmspectrum_protect_client
8.1.7.0 ≤
𝑥
≤ 8.1.9.1
ibmspectrum_protect_client
8.1.9.0 ≤
𝑥
≤ 8.1.9.1
ibmspectrum_protect_for_space_management
8.1.7.0 ≤
𝑥
≤ 8.1.9.1
ibmspectrum_protect_for_space_management
8.1.9.0 ≤
𝑥
≤ 8.1.9.1
𝑥
= Vulnerable software versions