{ "schema_version": "1.4.0", "id": "GHSA-vqq4-px95-x64f", "modified": "2022-05-24T17:27:28Z", "published": "2022-05-24T17:27:28Z", "aliases": [ "CVE-2020-4545" ], "details": "IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183190.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-4545" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/183190" }, { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/6326537" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-09-04T14:15:00Z" } }