CVE-2020-4434
Summary
| CVE | CVE-2020-4434 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-10 13:15:00 UTC |
| Updated | 2020-06-15 19:06:00 UTC |
| Description | Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900. |
Risk And Classification
Problem Types: CWE-120
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Aspera Application Platform On Demand | All | All | All | All |
| Application | Ibm | Aspera Faspex On Demand | All | All | All | All |
| Application | Ibm | Aspera High-speed Transfer Endpoint | All | All | All | All |
| Application | Ibm | Aspera High-speed Transfer Server | All | All | All | All |
| Application | Ibm | Aspera High-speed Transfer Server For Cloud Pak For Integration | All | All | All | All |
| Application | Ibm | Aspera Proxy Server | All | All | All | All |
| Application | Ibm | Aspera Server On Demand | All | All | All | All |
| Application | Ibm | Aspera Shares On Demand | All | All | All | All |
| Application | Ibm | Aspera Streaming | All | All | All | All |
| Application | Ibm | Aspera Transfer Cluster Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: Various vulnerabilities affecting certain Aspera applications (CVE-2020-4432, CVE-2020-4433, CVE-2020-4434, CVE-2020-4435, CVE-2020-4436) | CONFIRM | www.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.