VYPR
Unrated severityNVD Advisory· Published Aug 3, 2020· Updated Sep 16, 2024

CVE-2020-4552

CVE-2020-4552

Description

IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183320.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM i2 Analyst Notebook 9.2.1 memory corruption allows local attackers to execute arbitrary code via a crafted file.

Vulnerability

IBM i2 Analyst Notebook version 9.2.1 is affected by a memory corruption vulnerability [1]. The bug resides in the parsing of specially-crafted files. An attacker can trigger the vulnerability by crafting a malicious file that exploits the memory corruption when opened by a user. The vulnerability is present in the default configuration; no special settings are required.

Exploitation

Exploitation requires a local attacker to convince a victim to open a malicious file. The attacker must have the ability to deliver the file to the victim (e.g., via email, download, or removable media). No authentication is needed, but user interaction is required. The attacker does not need any special privileges on the system. The sequence involves crafting a file that triggers memory corruption upon parsing by the application.

Impact

Successful exploitation allows the attacker to execute arbitrary code on the victim's system with the privileges of the user running IBM i2 Analyst Notebook. This can lead to full compromise of the affected system, including data theft, installation of malware, or further lateral movement. The CVSS base score is 7.8 (High) [1].

Mitigation

IBM has released a security update to address this vulnerability. Users should apply the latest fix pack or update as specified in the IBM security bulletin [1]. No workarounds are documented. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.