High severity7.5NVD Advisory· Published Jun 10, 2020· Updated Jun 17, 2026
CVE-2020-4436
CVE-2020-4436
Description
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21- cpe:2.3:a:ibm:aspera_application_platform_on_demand:*:*:*:*:*:*:*:*Range: <=3.7.4
cpe:2.3:a:ibm:aspera_high-speed_transfer_endpoint:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:ibm:aspera_high-speed_transfer_endpoint:*:*:*:*:*:*:*:*range: <=3.9.3
- cpe:2.3:a:ibm:aspera_high-speed_transfer_server:*:*:*:*:*:*:*:*range: <=3.9.3
- (no CPE)range: 3.9.3
- (no CPE)range: 3.9.3
- cpe:2.3:a:ibm:aspera_high-speed_transfer_server_for_cloud_pak_for_integration:*:*:*:*:*:*:*:*Range: <=3.9.10
- cpe:2.3:a:ibm:aspera_transfer_cluster_manager:*:*:*:*:*:*:*:*Range: <=1.3.1
- IBM/Aspera Application Platform On Demandv5Range: 3.7.4
- IBM/Aspera Faspex On Demandv5Range: 3.7.4
- IBM/Aspera High-Speed Transfer Server for Cloud Pak for Integration (CP4I)v5Range: 3.9.10
- IBM/Aspera Proxy Serverv5Range: 1.4.3
- IBM/Aspera Server On Demandv5Range: 3.7.4
- Range: 3.7.4
- IBM/Aspera Streamingv5Range: 3.9.3
- IBM/Aspera Transfer Cluster Managerv5Range: 1.3.1
Patches
Vulnerability mechanics
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/180902nvdVDB EntryVendor Advisory
- www.ibm.com/support/pages/node/6221324nvdVendor Advisory
News mentions
0No linked articles in our index yet.