{"api_version":"1","generated_at":"2026-07-23T10:28:49+00:00","cve":"CVE-2020-4703","urls":{"html":"https://cve.report/CVE-2020-4703","api":"https://cve.report/api/cve/CVE-2020-4703.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-4703","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-4703"},"summary":{"title":"CVE-2020-4703","description":"IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2020-09-15 14:15:00","updated_at":"2020-09-16 00:46:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/187188","name":"ibm-spectrum-cve20204703-file-upload (187188)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.ibm.com/support/pages/node/6328867","name":"https://www.ibm.com/support/pages/node/6328867","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: Directory Traversal and Execution of Arbitrary Code vulnerabilities in IBM Spectrum Protect Plus (CVE-2020-4711, CVE-2020-4703)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-4703","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-4703","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"4703","vulnerable":"1","versionEndIncluding":"10.1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"spectrum_protect_plus","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"STATE":"PUBLIC","ID":"CVE-2020-4703","ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2020-09-14T00:00:00"},"references":{"reference_data":[{"name":"https://www.ibm.com/support/pages/node/6328867","title":"IBM Security Bulletin 6328867 (Spectrum Protect Plus)","refsource":"CONFIRM","url":"https://www.ibm.com/support/pages/node/6328867"},{"refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/187188","title":"X-Force Vulnerability Report","name":"ibm-spectrum-cve20204703-file-upload (187188)"}]},"data_type":"CVE","description":{"description_data":[{"value":"IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.","lang":"eng"}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"version":{"version_data":[{"version_value":"10.1.0"},{"version_value":"10.1.6"}]},"product_name":"Spectrum Protect Plus"}]}}]}},"data_version":"4.0","data_format":"MITRE","problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Gain Privileges"}]}]},"impact":{"cvssv3":{"TM":{"RL":"O","RC":"C","E":"U"},"BM":{"PR":"L","C":"H","UI":"R","SCORE":"8.000","I":"H","AV":"N","S":"U","AC":"L","A":"H"}}}},"nvd":{"publishedDate":"2020-09-15 14:15:00","lastModifiedDate":"2020-09-16 00:46:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6},"severity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:spectrum_protect_plus:*:*:*:*:*:*:*:*","versionStartIncluding":"10.1.0","versionEndIncluding":"10.1.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"4703","Ordinal":"164731","Title":"CVE-2020-4703","CVE":"CVE-2020-4703","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"4703","Ordinal":"1","NoteData":"IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"4703","Ordinal":"2","NoteData":"2020-09-15","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"4703","Ordinal":"3","NoteData":"2020-09-15","Type":"Other","Title":"Modified"}]}}}