← Vulnerability feed

Vulnerability record · CVE-2020-4222 · published 24 February 2020

CVE-2020-4222: Ibm spectrum protect os command injection vulnerability

Ibm · Spectrum Protect

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091.

9.8 CVSS 3.1 Critical EPSS 15% · top 3.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4222 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-4415Ibm spectrum protect improper input validation vulnerabilityIBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote…EPSS 8.1%9.8CVE-2020-4210Ibm spectrum protect os command injection vulnerabilityIBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …EPSS 15%9.8CVE-2020-4211IBM Spectrum Protect Plus OS command injection via crafted HTTP commandIBM Spectrum Protect Plus 10.1.0 and 10.1.5 contain an OS command injection flaw (CWE-78) reachable through a specially crafted HTTP command. A remot…EPSS 71%analysed9.8CVE-2020-4212Ibm spectrum protect improper input validation vulnerabilityIBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …EPSS 15%9.8CVE-2020-4213Ibm spectrum protect os command injection vulnerabilityIBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …EPSS 15%8.8CVE-2022-22394Ibm spectrum protect vulnerabilityThe IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access co…EPSS 2.2%7.8CVE-2019-4267Ibm spectrum protect memory buffer overflow vulnerabilityThe IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow execution of arbitrary code on the lo…EPSS 0.44%7.5CVE-2020-4559Ibm spectrum protect improper input validation vulnerabilityIBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2020-4222), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.