CVE-2020-4434

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
10/06/2020
Last modified:
15/06/2020

Description

Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:aspera_application_platform_on_demand:*:*:*:*:*:*:*:* 3.7.4 (including)
cpe:2.3:a:ibm:aspera_faspex_on_demand:*:*:*:*:*:*:*:* 3.7.4 (including)
cpe:2.3:a:ibm:aspera_high-speed_transfer_endpoint:*:*:*:*:*:*:*:* 3.9.3 (including)
cpe:2.3:a:ibm:aspera_high-speed_transfer_server:*:*:*:*:*:*:*:* 3.9.3 (including)
cpe:2.3:a:ibm:aspera_high-speed_transfer_server_for_cloud_pak_for_integration:*:*:*:*:*:*:*:* 3.9.10 (including)
cpe:2.3:a:ibm:aspera_proxy_server:*:*:*:*:*:*:*:* 1.4.3 (including)
cpe:2.3:a:ibm:aspera_server_on_demand:*:*:*:*:*:*:*:* 3.7.4 (including)
cpe:2.3:a:ibm:aspera_shares_on_demand:*:*:*:*:*:*:*:* 3.7.4 (including)
cpe:2.3:a:ibm:aspera_streaming:*:*:*:*:*:*:*:* 3.9.3 (including)
cpe:2.3:a:ibm:aspera_transfer_cluster_manager:*:*:*:*:*:*:*:* 1.3.1 (including)