CVE-2020-4435
Summary
| CVE | CVE-2020-4435 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-10 13:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Aspera Application Platform On Demand | All | All | All | All |
| Application | Ibm | Aspera Faspex On Demand | All | All | All | All |
| Application | Ibm | Aspera High-speed Transfer Endpoint | All | All | All | All |
| Application | Ibm | Aspera High-speed Transfer Server | All | All | All | All |
| Application | Ibm | Aspera High-speed Transfer Server For Cloud Pak For Integration | All | All | All | All |
| Application | Ibm | Aspera Proxy Server | All | All | All | All |
| Application | Ibm | Aspera Server On Demand | All | All | All | All |
| Application | Ibm | Aspera Shares On Demand | All | All | All | All |
| Application | Ibm | Aspera Streaming | All | All | All | All |
| Application | Ibm | Aspera Transfer Cluster Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Various vulnerabilities affecting certain Aspera applications (CVE-2020-4432, CVE-2020-4433, CVE-2020-4434, CVE-2020-4435, CVE-2020-4436) | CONFIRM | www.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.