CVE-2019-4383: High severity IBM Spectrum Protect Plus vulnerability
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected restore operation may result in an escalation of user privileges. IBM X-Force ID: 162165.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4383?
CVE-2019-4383 has a medium severity rating due to the potential for privilege escalation during a redirected restore operation.
How do I fix CVE-2019-4383?
To fix CVE-2019-4383, upgrade IBM Spectrum Protect Plus to a version that is not vulnerable, specifically beyond version 10.1.3.
What versions of IBM Spectrum Protect Plus are affected by CVE-2019-4383?
CVE-2019-4383 affects IBM Spectrum Protect Plus versions 10.1.0, 10.1.1, 10.1.2, and 10.1.3.
What databases are impacted by CVE-2019-4383?
CVE-2019-4383 impacts the use of IBM Spectrum Protect Plus in protecting Oracle and MongoDB databases.
Is there a known exploit for CVE-2019-4383?
Yes, CVE-2019-4383 has potential exploit scenarios related to privilege escalation through redirected restore operations.