CVE-2020-4406
Last modified
CVE-2020-4406 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. EPSS estimates a 0.82% chance of exploitation in the next 30 days.
Description
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Spectrum Protect Client | >= 8.1.7.0, <= 8.1.9.1 |
| Ibm | Spectrum Protect Client | >= 8.1.9.0, <= 8.1.9.1 |
| Ibm | Spectrum Protect For Space Management | >= 8.1.7.0, <= 8.1.9.1 |
| Ibm | Spectrum Protect For Space Management | >= 8.1.9.0, <= 8.1.9.1 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/179488VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6221448Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/179488VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6221448Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-4406?
How severe is CVE-2020-4406?
How do I fix CVE-2020-4406?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-4395IBM Security Access Manager Appliance 9.0.7 does not invalid…5.4
- CVE-2020-4396IBM Jazz Foundation and IBM Engineering products are vulnera…5.4
- CVE-2020-4397IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive…5.9
- CVE-2020-4399IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an auth…6.5
- CVE-2020-4400IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate …7.5
- CVE-2020-4405IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose pote…4.3
- CVE-2020-4408The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for…4.6
- CVE-2020-4409IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a re…8.2
- CVE-2020-4410IBM Jazz Foundation and IBM Engineering products could allow…4.3
- CVE-2020-4411The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 thro…7.1
- CVE-2020-4412The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 thro…5.3
- CVE-2020-4413IBM Security Secret Server 10.7 could allow a remote attacke…5.9
Are you affected by CVE-2020-4406?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
