First published: Tue May 07 2019(Updated: )
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Control | >=5.2.8<=5.2.17.2 | |
IBM Spectrum Control | >=5.3.0<=5.3.1 | |
IBM Tivoli Storage Productivity Center | >=5.2.0<=5.2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4071 has been classified as a high severity vulnerability due to the risk of remote code execution.
To fix CVE-2019-4071, upgrade to IBM Spectrum Control versions 5.3.1 or later or to any patched version of IBM Tivoli Storage Productivity Center.
CVE-2019-4071 affects IBM Spectrum Control versions 5.2.1 through 5.2.17 and IBM Tivoli Storage Productivity Center versions 5.2.0 through 5.2.7.1.
The impact of CVE-2019-4071 is the potential for a remote attacker to execute arbitrary commands on the affected system.
Yes, CVE-2019-4071 is a network-based vulnerability that can be exploited by attackers remotely.