High severity7.5NVD Advisory· Published Jun 10, 2020· Updated Jun 17, 2026
CVE-2020-4433
CVE-2020-4433
Description
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21- Range: 3.7.4
3.9.3+ 3 more
- (no CPE)range: 3.9.3
- (no CPE)range: 3.9.3
- cpe:2.3:a:ibm:aspera_high-speed_transfer_endpoint:*:*:*:*:*:*:*:*range: <=3.9.3
- cpe:2.3:a:ibm:aspera_high-speed_transfer_server:*:*:*:*:*:*:*:*range: <=3.9.3
3.7.4+ 1 more
- (no CPE)range: 3.7.4
- cpe:2.3:a:ibm:aspera_faspex_on_demand:*:*:*:*:*:*:*:*range: <=3.7.4
3.7.4+ 1 more
- (no CPE)range: 3.7.4
- cpe:2.3:a:ibm:aspera_server_on_demand:*:*:*:*:*:*:*:*range: <=3.7.4
3.9.10+ 1 more
- (no CPE)range: 3.9.10
- cpe:2.3:a:ibm:aspera_high-speed_transfer_server_for_cloud_pak_for_integration:*:*:*:*:*:*:*:*range: <=3.9.10
3.9.3+ 1 more
- (no CPE)range: 3.9.3
- cpe:2.3:a:ibm:aspera_streaming:*:*:*:*:*:*:*:*range: <=3.9.3
1.3.1+ 1 more
- (no CPE)range: 1.3.1
- cpe:2.3:a:ibm:aspera_transfer_cluster_manager:*:*:*:*:*:*:*:*range: <=1.3.1
3.7.4+ 1 more
- (no CPE)range: 3.7.4
- cpe:2.3:a:ibm:aspera_application_platform_on_demand:*:*:*:*:*:*:*:*range: <=3.7.4
1.4.3+ 1 more
- (no CPE)range: 1.4.3
- cpe:2.3:a:ibm:aspera_proxy_server:*:*:*:*:*:*:*:*range: <=1.4.3
Patches
Vulnerability mechanics
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/180814nvdVDB EntryVendor Advisory
- www.ibm.com/support/pages/node/6221324nvdVendor Advisory
News mentions
0No linked articles in our index yet.