Vulnerability Description
IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Spectrum Virtualize | 8.3.1 |
| Ibm | Flashsystem V5000 Firmware | 8.3.1 |
| Ibm | Flashsystem V5000 | - |
| Ibm | Flashsystem V7200 Firmware | 8.3.1 |
| Ibm | Flashsystem V7200 | - |
| Ibm | Flashsystem V9000 Firmware | 8.3.1 |
| Ibm | Flashsystem V9000 | - |
| Ibm | Flashsystem V9100 Firmware | 8.3.1 |
| Ibm | Flashsystem V9100 | - |
| Ibm | Flashsystem V9200 Firmware | 8.3.1 |
| Ibm | Flashsystem V9200 | - |
| Ibm | San Volume Controller Firmware | 8.3.1 |
| Ibm | San Volume Controller | - |
| Ibm | Storwize V5000 Firmware | 8.3.1 |
| Ibm | Storwize V5000 | - |
| Ibm | Storwize V5000E Firmware | 8.3.1 |
| Ibm | Storwize V5000E | - |
| Ibm | Storwize V5100 Firmware | 8.3.1 |
| Ibm | Storwize V5100 | - |
| Ibm | Storwize V7000 Firmware | 8.3.1 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186678VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6260199PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186678VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6260199PatchVendor Advisory
FAQ
What is CVE-2020-4686?
CVE-2020-4686 is a vulnerability with a CVSS score of 8.1 (HIGH). IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678.
How severe is CVE-2020-4686?
CVE-2020-4686 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-4686?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Spectrum Virtualize, Ibm Flashsystem V5000 Firmware, Ibm Flashsystem V5000, Ibm Flashsystem V7200 Firmware, Ibm Flashsystem V7200.