CVE-2020-4955
Description
IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an unspecified servlet request with specially crafted input parameters, an attacker could exploit this vulnerability to load a malicious .dll with elevated privileges. IBM X-Force ID: 192155.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Spectrum Protect Operations Center 7.1 and 8.1 are vulnerable to remote code execution via improper parameter validation in a servlet request, allowing loading of a malicious DLL with elevated privileges.
Vulnerability
IBM Spectrum Protect Operations Center versions 7.1 and 8.1 are affected by a remote code execution vulnerability (CVE-2020-4955) due to improper parameter validation in an unspecified servlet. An attacker can craft a servlet request with specially crafted input parameters to load a malicious dynamic-link library (.dll) with elevated privileges. The CVSS vector (CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates the attack requires adjacent network access, high complexity, and low privileges, with no user interaction [1].
Exploitation
To exploit this vulnerability, an attacker must be on the adjacent network and possess low-level privileges (e.g., a valid user account). The attacker sends a specially crafted servlet request to the Operations Center. The exact servlet endpoint is not disclosed, but the crafted input parameters trigger improper validation, allowing the attacker to load a malicious .dll file. The exploitation does not require user interaction [1].
Impact
Successful exploitation allows the attacker to execute arbitrary code on the system with elevated privileges. Due to the scope change (S:C), the compromise can affect resources beyond the vulnerable component, leading to full compromise of confidentiality, integrity, and availability [1].
Mitigation
IBM has released a fix for version 8.1.11 (8.1.11.100) as of April 15, 2021. Users running 8.1 should upgrade to 8.1.11.100 or later. For version 7.1, no fix is provided; users are advised to upgrade to a supported version (e.g., 8.1.11.100). No workarounds are documented in the available reference [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 7.1, 8.1
- IBM/Spectrum Protect Operations Centerv5Range: 8.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/192155mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6404966mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.