CVE-2019-4236: Medium severity ibm spectrum protect vulnerability
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-4236?
CVE-2019-4236 is a vulnerability in IBM Spectrum Protect 7.1.x that silently skips Access Control List (ACL) entries during backup or archive operations for HP-UX VxFS objects with more than twelve ACL entries.
How does CVE-2019-4236 affect IBM Spectrum Protect?
CVE-2019-4236 affects IBM Spectrum Protect 7.1.x and potentially allows a local attacker to gain unauthorized access to files by bypassing ACL security.
What is the severity of CVE-2019-4236?
CVE-2019-4236 has a severity rating of 4.4, which is classified as medium.
Is HP-UX vulnerable to CVE-2019-4236?
No, HP-UX is not vulnerable to CVE-2019-4236 as stated in the vulnerability description.
How can I mitigate the impact of CVE-2019-4236?
To mitigate the impact of CVE-2019-4236, IBM Spectrum Protect users should apply the recommended fix or update provided by IBM.