Vulnerabilities > IBM > Spectrum Protect Plus > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-06-15 CVE-2020-4469 OS Command Injection vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system.
network
low complexity
ibm CWE-78
critical
10.0
2020-03-31 CVE-2020-4206 Improper Input Validation vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-20
critical
9.0
2020-03-31 CVE-2020-4241 OS Command Injection vulnerability in IBM Spectrum Protect Plus and Spectrum Scale
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system.
network
low complexity
ibm CWE-78
critical
9.0
2020-03-31 CVE-2020-4242 OS Command Injection vulnerability in IBM Spectrum Protect Plus and Spectrum Scale
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system.
network
low complexity
ibm CWE-78
critical
9.0