First published: Mon Jul 22 2019(Updated: )
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect | >=7.1.0.0<=7.1.8.5 | |
HP HP-UX |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4236 is a vulnerability in IBM Spectrum Protect 7.1.x that silently skips Access Control List (ACL) entries during backup or archive operations for HP-UX VxFS objects with more than twelve ACL entries.
CVE-2019-4236 affects IBM Spectrum Protect 7.1.x and potentially allows a local attacker to gain unauthorized access to files by bypassing ACL security.
CVE-2019-4236 has a severity rating of 4.4, which is classified as medium.
No, HP-UX is not vulnerable to CVE-2019-4236 as stated in the vulnerability description.
To mitigate the impact of CVE-2019-4236, IBM Spectrum Protect users should apply the recommended fix or update provided by IBM.