First published: Tue Apr 02 2019(Updated: )
IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions. IBM X-Force ID: 157981.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect | =8.1.7 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-4093.
The severity of CVE-2019-4093 is medium with a CVSS score of 4.4.
CVE-2019-4093 allows a user to restore files and directories using IBM Spectrum Protect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions.
IBM Tivoli Storage Manager (IBM Spectrum Protect) version 8.1.7 is affected by CVE-2019-4093.
You can find more information about CVE-2019-4093 on the IBM support website and the IBM X-Force ID website.