First published: Mon Jul 01 2019(Updated: )
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on the system, caused by loading a specially crafted library loaded by the dsmqsan module. By setting up such a library, a local attacker could exploit this vulnerability to gain root privileges on the vulnerable system. IBM X-Force ID: 157511.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Operations Center | >=7.1.0.000<=7.1.9.200 | |
IBM Spectrum Protect Operations Center | >=8.1.0.000<=8.1.7.000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4088 is a vulnerability in IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents that allows a local attacker to gain elevated privileges on the system.
CVE-2019-4088 occurs when a specially crafted library is loaded by the dsmqsan module.
The affected software versions for CVE-2019-4088 are IBM Spectrum Protect Servers 7.1 to 7.1.9.200 and 8.1 to 8.1.7.000.
The severity of CVE-2019-4088 is high, with a CVSS score of 7.8.
To fix CVE-2019-4088, users should apply the necessary patches or upgrades provided by IBM.