First published: Mon Jul 01 2019(Updated: )
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system. IBM X-Force ID: 161667,
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | =10.1.1 | |
IBM Spectrum Protect Plus | =10.1.2 | |
IBM Spectrum Protect Plus | =10.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4357 is rated as a critical vulnerability due to the potential for arbitrary code execution.
To mitigate CVE-2019-4357, upgrade to a patched version of IBM Spectrum Protect Plus that resolves the issue.
CVE-2019-4357 affects IBM Spectrum Protect Plus versions 10.1.0, 10.1.2, and 10.1.3.
CVE-2019-4357 allows an attacker to execute arbitrary code on the system through a redirected restore operation.
Yes, CVE-2019-4357 impacts the protection of Oracle, DB2, and MongoDB databases when using the affected versions of IBM Spectrum Protect Plus.