CVE-2020-4435

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
10/06/2020
Last modified:
21/07/2021

Description

Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:aspera_application_platform_on_demand:*:*:*:*:*:*:*:* 3.7.4 (including)
cpe:2.3:a:ibm:aspera_faspex_on_demand:*:*:*:*:*:*:*:* 3.7.4 (including)
cpe:2.3:a:ibm:aspera_high-speed_transfer_endpoint:*:*:*:*:*:*:*:* 3.9.3 (including)
cpe:2.3:a:ibm:aspera_high-speed_transfer_server:*:*:*:*:*:*:*:* 3.9.3 (including)
cpe:2.3:a:ibm:aspera_high-speed_transfer_server_for_cloud_pak_for_integration:*:*:*:*:*:*:*:* 3.9.10 (including)
cpe:2.3:a:ibm:aspera_proxy_server:*:*:*:*:*:*:*:* 1.4.3 (including)
cpe:2.3:a:ibm:aspera_server_on_demand:*:*:*:*:*:*:*:* 3.7.4 (including)
cpe:2.3:a:ibm:aspera_shares_on_demand:*:*:*:*:*:*:*:* 3.7.4 (including)
cpe:2.3:a:ibm:aspera_streaming:*:*:*:*:*:*:*:* 3.9.3 (including)
cpe:2.3:a:ibm:aspera_transfer_cluster_manager:*:*:*:*:*:*:*:* 1.3.1 (including)