CVE-2019-4357: High severity ibm storage protect plus vulnerability
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system. IBM X-Force ID: 161667,
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4357?
CVE-2019-4357 is rated as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2019-4357?
To mitigate CVE-2019-4357, upgrade to a patched version of IBM Spectrum Protect Plus that resolves the issue.
What systems are affected by CVE-2019-4357?
CVE-2019-4357 affects IBM Spectrum Protect Plus versions 10.1.0, 10.1.2, and 10.1.3.
What actions will CVE-2019-4357 allow an attacker to perform?
CVE-2019-4357 allows an attacker to execute arbitrary code on the system through a redirected restore operation.
Is CVE-2019-4357 specific to any database?
Yes, CVE-2019-4357 impacts the protection of Oracle, DB2, and MongoDB databases when using the affected versions of IBM Spectrum Protect Plus.