CVE-2019-4406: Medium severity ibm storage protect backup-archive client vulnerability
IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications. IBM X-Force ID: 162477.
Other sources
The IBM Spectrum Protect Client may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-4406.
What is the severity of CVE-2019-4406?
The severity of CVE-2019-4406 is medium (4.4).
Which IBM Spectrum Protect Client versions are affected by CVE-2019-4406?
IBM Spectrum Protect Backup-Archive Client versions 7.1.0.0 to 7.1.8.6 and versions 8.1.0.0 to 8.1.8.0 are affected by CVE-2019-4406.
How can CVE-2019-4406 be exploited?
CVE-2019-4406 can be exploited through a denial of service attack caused by a timing issue between client and server TCP/IP communications.
Where can I find more information about CVE-2019-4406?
You can find more information about CVE-2019-4406 on IBM's official support page and the IBM X-Force ID: 162477 vulnerability report.