HIGH · 7.8

CVE-2020-4278

IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges due to weak file permissions when specific debug s...

Vulnerability Description

IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges due to weak file permissions when specific debug settings are enabled in a Linux or Unix enviornment. IBM X-Force ID: 176137.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IbmPlatform Lsf9.1
IbmSpectrum Computing For High Performance Analytics10.2
IbmSpectrum Lsf10.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-4278?

CVE-2020-4278 is a vulnerability with a CVSS score of 7.8 (HIGH). IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges due to weak file permissions when specific debug s...

How severe is CVE-2020-4278?

CVE-2020-4278 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-4278?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Platform Lsf, Ibm Spectrum Computing For High Performance Analytics, Ibm Spectrum Lsf.