{"api_version":"1","generated_at":"2026-07-24T01:39:54+00:00","cve":"CVE-2020-4693","urls":{"html":"https://cve.report/CVE-2020-4693","api":"https://cve.report/api/cve/CVE-2020-4693.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-4693","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-4693"},"summary":{"title":"CVE-2020-4693","description":"IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the system, caused by improper validation of data prior to export. IBM X-Force ID: 186782.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2020-09-02 19:15:00","updated_at":"2020-09-10 18:19:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/186782","name":"ibm-spectrum-cve20204693-code-exec (186782)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.ibm.com/support/pages/node/6325341","name":"https://www.ibm.com/support/pages/node/6325341","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin:  Code injection vulnerability in IBM Spectrum Protect Operations Center (CVE-2020-4693)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-4693","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-4693","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"4693","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4693","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4693","vulnerable":"1","versionEndIncluding":"7.1.10.000","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"spectrum_protect_operations_center","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4693","vulnerable":"1","versionEndIncluding":"8.1.9.000","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"spectrum_protect_operations_center","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4693","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4693","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4693","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4693","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-4693","qid":"377883","title":"IBM Spectrum Protect Operations Center Code injection vulnerability (CVE-2020-4693)"}]},"source_records":{"cve_program":{"references":{"reference_data":[{"title":"IBM Security Bulletin 6325341 (Spectrum Protect Operations Center)","url":"https://www.ibm.com/support/pages/node/6325341","name":"https://www.ibm.com/support/pages/node/6325341","refsource":"CONFIRM"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/186782","title":"X-Force Vulnerability Report","name":"ibm-spectrum-cve20204693-code-exec (186782)","refsource":"XF"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"Gain Access","lang":"eng"}]}]},"impact":{"cvssv3":{"TM":{"RL":"O","E":"U","RC":"C"},"BM":{"I":"H","AC":"L","A":"N","UI":"N","PR":"N","S":"U","AV":"N","C":"H","SCORE":"9.100"}}},"data_format":"MITRE","data_version":"4.0","data_type":"CVE","description":{"description_data":[{"lang":"eng","value":"IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the system, caused by improper validation of data prior to export. IBM X-Force ID: 186782."}]},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Spectrum Protect Operations Center","version":{"version_data":[{"version_value":"7.1.0.000"},{"version_value":"8.1.0.000"},{"version_value":"7.1.10"},{"version_value":"8.1.9"}]}}]},"vendor_name":"IBM"}]}},"CVE_data_meta":{"DATE_PUBLIC":"2020-09-01T00:00:00","STATE":"PUBLIC","ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2020-4693"}},"nvd":{"publishedDate":"2020-09-02 19:15:00","lastModifiedDate":"2020-09-10 18:19:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:spectrum_protect_operations_center:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1.0.000","versionEndIncluding":"7.1.10.000","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:spectrum_protect_operations_center:*:*:*:*:*:*:*:*","versionStartIncluding":"8.1.0.000","versionEndIncluding":"8.1.9.000","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"4693","Ordinal":"164721","Title":"CVE-2020-4693","CVE":"CVE-2020-4693","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"4693","Ordinal":"1","NoteData":"IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the system, caused by improper validation of data prior to export. IBM X-Force ID: 186782.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"4693","Ordinal":"2","NoteData":"2020-09-02","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"4693","Ordinal":"3","NoteData":"2020-09-02","Type":"Other","Title":"Modified"}]}}}